Vulnerability Name: | CVE-2000-0597 (CCN-4842) | ||||||||
Assigned: | 2000-06-27 | ||||||||
Published: | 2000-06-27 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Jun 27 2000 - 06:43:05 CDT IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs Source: MITRE Type: CNA CVE-2000-0597 Source: CCN Type: CERT Advisory CA-2000-16 Microsoft 'IE Script'/Access/OBJECT Tag Vulnerability Source: CCN Type: CIAC Information Bulletin K-061 Microsoft "Office HTML" & "IE" Script Vulnerabilities Source: CCN Type: Microsoft Security Bulletin MS00-049 Patch Available for 'The Office HTML Script' Vulnerability and a Workaround for 'The IE Script' Vulnerability Source: CCN Type: OSVDB ID: 1428 Microsoft IE/Office ActiveX Object Execution Source: BID Type: UNKNOWN 1399 Source: CCN Type: BID-1399 Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20000627 IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs Source: MS Type: UNKNOWN MS00-049 Source: XF Type: UNKNOWN ie-powerpoint-activex-object-execute(4842) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |