First published: Tue Jun 27 2000(Updated: )
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2000 | |
Microsoft PowerPoint 2010 | =97 | |
Microsoft PowerPoint 2010 | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0597 has a moderate severity level as it allows unauthorized file saving which can lead to potential data exposure.
To mitigate the effects of CVE-2000-0597, it is recommended to apply the necessary Microsoft patches for affected versions of Excel and PowerPoint.
CVE-2000-0597 affects Microsoft Excel 2000, PowerPoint 97, and PowerPoint 2000.
Exploitation of CVE-2000-0597 can allow attackers to save files to arbitrary locations on a victim's system.
A potential workaround for CVE-2000-0597 is to change settings in Internet Explorer or email clients to limit scripts from running.