First published: Fri Oct 20 2000(Updated: )
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Access 2010 | =2000 | |
Microsoft Office Word | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0788 is considered a moderate severity vulnerability due to its potential to execute arbitrary commands via VBA scripts.
To fix CVE-2000-0788, users should disable macros or change security settings in Microsoft Word and Access to prevent unauthorized execution.
CVE-2000-0788 affects users of Microsoft Word 2000 and Microsoft Access 2000.
CVE-2000-0788 is a vulnerability related to the execution of arbitrary commands through the Mail Merge tool.
Yes, CVE-2000-0788 can be exploited remotely if an attacker can convince a user to open a malicious document containing VBA scripts.