CVE-2001-0628: High severity Microsoft Word vulnerability
Published Aug 14, 2001
·Updated
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
Affected Software
1 affected component
Microsoft Word=2000
Remediation
Patch Available
Event History
Aug 14, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0628?
CVE-2001-0628 is considered a moderate vulnerability as it allows local attackers to execute arbitrary macros.
2
How do I fix CVE-2001-0628?
To fix CVE-2001-0628, users should apply all available security updates or consider upgrading to a newer version of Microsoft Word.
3
Who is affected by CVE-2001-0628?
CVE-2001-0628 affects users of Microsoft Word 2000 who utilize AutoRecovery files.
4
What type of attacks can exploit CVE-2001-0628?
CVE-2001-0628 can be exploited by local attackers to execute malicious macros on the affected system.
5
Is CVE-2001-0628 a zero-day vulnerability?
No, CVE-2001-0628 is not a zero-day vulnerability as it was disclosed publicly and has available fixes.