CVE-1999-0717: Low severity Microsoft Excel vulnerability
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Excel 97from your environment.Uninstall or otherwise prevent the use of Microsoft Excel 97 on systems where it is not required until a vendor-provided fix is available.
- Configuration
Ensure the virus warning mechanism in Microsoft Excel 97 is enabled and verify the setting remains enabled on affected systems.
Microsoft Excel 97 virus warning mechanism = enabled - Compensating control
Restrict exposure of systems running Microsoft Excel 97 to untrusted networks and users (for example, block remote access from untrusted networks and avoid opening Excel 97 documents from untrusted sources) to reduce the risk of remote attackers disabling the virus-warning mechanism.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0717?
CVE-1999-0717 has been classified as a moderate severity vulnerability.
How do I fix CVE-1999-0717?
To fix CVE-1999-0717, ensure that you apply the relevant updates or patches provided by Microsoft for the affected products.
Which software is affected by CVE-1999-0717?
CVE-1999-0717 affects multiple versions of Microsoft Excel and various Windows operating systems including Windows 95, 98, NT, and 2000.
Can CVE-1999-0717 be exploited remotely?
Yes, CVE-1999-0717 can be exploited remotely by an attacker to disable the virus warning mechanism in Microsoft Excel.
What impact does CVE-1999-0717 have on users?
The impact of CVE-1999-0717 allows malicious files to be opened without triggering virus warnings, potentially leading to infected systems.