CVE-2001-0240: Medium severity Microsoft Word vulnerability
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0240?
CVE-2001-0240 is considered a critical vulnerability due to the potential for automated macro execution without user consent.
How do I fix CVE-2001-0240?
To fix CVE-2001-0240, users should upgrade to Microsoft Word 2002 or later, which addresses this vulnerability.
What versions of Microsoft Word are affected by CVE-2001-0240?
CVE-2001-0240 affects Microsoft Word versions 97, 98, and 2000 on both Windows and Mac platforms.
What type of attack does CVE-2001-0240 facilitate?
CVE-2001-0240 facilitates attacks that utilize embedded macros in Rich Text Format (RTF) documents.
Who is at risk of exploiting CVE-2001-0240?
Users of older versions of Microsoft Word, particularly those who open RTF documents, are at risk of exploitation from CVE-2001-0240.