First published: Wed Jun 27 2001(Updated: )
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | =2000 | |
Microsoft Office Word | =97 | |
Microsoft Office Word | =98 | |
Microsoft Word for Mac | =98 | |
Microsoft Word for Mac | =2001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0240 is considered a critical vulnerability due to the potential for automated macro execution without user consent.
To fix CVE-2001-0240, users should upgrade to Microsoft Word 2002 or later, which addresses this vulnerability.
CVE-2001-0240 affects Microsoft Word versions 97, 98, and 2000 on both Windows and Mac platforms.
CVE-2001-0240 facilitates attacks that utilize embedded macros in Rich Text Format (RTF) documents.
Users of older versions of Microsoft Word, particularly those who open RTF documents, are at risk of exploitation from CVE-2001-0240.