Vulnerability Name: | CVE-1999-0354 | ||||||||
Assigned: | 1999-11-01 | ||||||||
Published: | 1999-11-01 | ||||||||
Updated: | 2021-07-22 | ||||||||
Summary: | Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | ALLOWS_OTHER_ACCESS | ||||||||
References: | Source: MITRE Type: CNA CVE-1999-0354 Source: MS Type: UNKNOWN MS99-002 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |