Vulnerability Name:

CVE-2000-0277 (CCN-4224)

Assigned:2000-04-03
Published:2000-04-03
Updated:2018-10-12
Summary:Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-254
References:Source: MITRE
Type: CNA
CVE-2000-0277

Source: CCN
Type: US-CERT VU#26493
MS Excel XLM Text Macro execution fails to trigger warning when default medium security set

Source: CCN
Type: Microsoft Security Bulletin MS00-022
Patch Available for "XLM Text Macro" Vulnerability

Source: OSVDB
Type: Broken Link
1272

Source: CCN
Type: OSVDB ID: 1272
Microsoft Excel XLM Arbitrary Macro Execution

Source: BID
Type: Third Party Advisory
1087

Source: CCN
Type: BID-1087
Microsoft Excel XML Vulnerability

Source: MS
Type: UNKNOWN
MS00-022

Source: XF
Type: UNKNOWN
excel-xlm(4224)

Source: CCN
Type: Microsoft Knowledge Base Article 255605
XL2000: Macro Virus Warning Does Not Appear When You Open a Text File That Contains XLM Code

Source: CCN
Type: Microsoft Knowledge Base Article 255606
XL97: Macro Virus Warning Does Not Appear When You Open a Text File That Contains XLM Code

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:excel:97:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:excel:2000:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:excel:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft excel 97
    microsoft excel 2000
    microsoft excel *