The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores