CVE-2000-0597
Published Jun 27, 2000
Last updated a year ago
Overview
- Description
- Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F55D42D5-7371-47C2-BF55-B7F51C19B61E" }, { "criteria": "cpe:2.3:a:microsoft:powerpoint:97:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FFA2986-0E47-43C0-938E-65FC15F13C53" }, { "criteria": "cpe:2.3:a:microsoft:powerpoint:2000:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E392539-ABF6-4B5C-AEC3-C54B51E0DB70" } ], "operator": "OR" } ] } ]