CVE-1999-0354: High severity Microsoft Word vulnerability

Published Nov 1, 1999
·
Updated

Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.

Affected Software

3 affected components
Microsoft Word=97
Microsoft Internet Explorer=4.0
Microsoft Internet Explorer=5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure Internet Explorer and Word 97 so that Word templates are not opened inside the browser and the user is prompted before any embedded Visual Basic or executable content is run.

    Internet Explorer / Microsoft Word 97 open templates/executable content in browser = disabled / prompt
  2. Configuration

    Disable automatic previewing/opening of email attachments and require user confirmation before opening Word templates or other attachments in Outlook.

    Microsoft Outlook attachment/preview handling = disabled / prompt
  3. Compensating control

    Block or strip Word template attachments (Word 97 templates) at the email gateway or mail server and restrict delivery of potentially executable Office template content to users.

  4. Operational

    Instruct users not to open or enable content in unsolicited or untrusted Word templates or email attachments; remove suspicious messages and attachments and report them to IT for analysis.

Event History

Nov 1, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0354?

CVE-1999-0354 has a high severity rating due to its ability to allow arbitrary execution of Visual Basic programs.

2

How do I fix CVE-1999-0354?

To fix CVE-1999-0354, users should update their versions of Internet Explorer or Microsoft Word as recommended by Microsoft security updates.

3

Which versions are affected by CVE-1999-0354?

CVE-1999-0354 affects Internet Explorer versions 4.0 and 5.0 and Microsoft Word 97.

4

What impact does CVE-1999-0354 have on my system?

CVE-1999-0354 can lead to unauthorized execution of scripts and code, potentially compromising system security.

5

Can CVE-1999-0354 be exploited through email?

Yes, CVE-1999-0354 can be exploited by viewing a malicious email in Outlook that contains a template with executable content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203