CVE-1999-0354: High severity Microsoft Word vulnerability
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure Internet Explorer and Word 97 so that Word templates are not opened inside the browser and the user is prompted before any embedded Visual Basic or executable content is run.
Internet Explorer / Microsoft Word 97 open templates/executable content in browser = disabled / prompt - Configuration
Disable automatic previewing/opening of email attachments and require user confirmation before opening Word templates or other attachments in Outlook.
Microsoft Outlook attachment/preview handling = disabled / prompt - Compensating control
Block or strip Word template attachments (Word 97 templates) at the email gateway or mail server and restrict delivery of potentially executable Office template content to users.
- Operational
Instruct users not to open or enable content in unsolicited or untrusted Word templates or email attachments; remove suspicious messages and attachments and report them to IT for analysis.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0354?
CVE-1999-0354 has a high severity rating due to its ability to allow arbitrary execution of Visual Basic programs.
How do I fix CVE-1999-0354?
To fix CVE-1999-0354, users should update their versions of Internet Explorer or Microsoft Word as recommended by Microsoft security updates.
Which versions are affected by CVE-1999-0354?
CVE-1999-0354 affects Internet Explorer versions 4.0 and 5.0 and Microsoft Word 97.
What impact does CVE-1999-0354 have on my system?
CVE-1999-0354 can lead to unauthorized execution of scripts and code, potentially compromising system security.
Can CVE-1999-0354 be exploited through email?
Yes, CVE-1999-0354 can be exploited by viewing a malicious email in Outlook that contains a template with executable content.