Vulnerability Name:

CVE-2001-0501 (CCN-6732)

Assigned:2001-06-21
Published:2001-06-21
Updated:2018-10-12
Summary:Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Fri Jun 22 2001 - 11:58:44 CDT
Fwd: Microsoft Word macro vulnerability advisory MS01-034

Source: MITRE
Type: CNA
CVE-2001-0501

Source: BUGTRAQ
Type: UNKNOWN
20010622 Fwd: Microsoft Word macro vulnerability advisory MS01-034

Source: CCN
Type: US-CERT VU#295867
Microsoft Word does not adequately validate macros embedded within malformed Word documents

Source: CCN
Type: Microsoft Security Bulletin MS01-034
Malformed Word Document Could Enable Macro to Run Automatically

Source: CCN
Type: OSVDB ID: 1867
Microsoft Word Document Macro Execution

Source: BID
Type: Patch, Vendor Advisory
2876

Source: CCN
Type: BID-2876
Microsoft Word Document Macro Execution Vulnerability

Source: MS
Type: UNKNOWN
MS01-034

Source: XF
Type: UNKNOWN
msword-macro-bypass-security(6732)

Source: XF
Type: UNKNOWN
msword-macro-bypass-security(6732)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:word:97:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:97:sr1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:97:sr2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:98:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:98:*:mac:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2000:sr1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2000:sr1a:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2000:sr2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2001:*:mac:*:*:*:*:*
  • OR cpe:/a:microsoft:word:*:*:*:*:*:*:*:* (Version <= 2002)

  • Configuration CCN 1:
  • cpe:/a:microsoft:word:97:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word:98:*:*:ja:*:*:*:*
  • OR cpe:/a:microsoft:word:98:sr1:mac_os:*:*:*:*:*
  • OR cpe:/a:microsoft:word:2002:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft word 97
    microsoft word 97 sr1
    microsoft word 97 sr2
    microsoft word 98
    microsoft word 98
    microsoft word 2000
    microsoft word 2000 sr1
    microsoft word 2000 sr1a
    microsoft word 2000 sr2
    microsoft word 2001
    microsoft word *
    microsoft word 97
    microsoft word 2000
    microsoft word 98
    microsoft word 98 sr1
    microsoft word 2002