First published: Tue Aug 14 2001(Updated: )
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0628 is considered a moderate vulnerability as it allows local attackers to execute arbitrary macros.
To fix CVE-2001-0628, users should apply all available security updates or consider upgrading to a newer version of Microsoft Word.
CVE-2001-0628 affects users of Microsoft Word 2000 who utilize AutoRecovery files.
CVE-2001-0628 can be exploited by local attackers to execute malicious macros on the affected system.
No, CVE-2001-0628 is not a zero-day vulnerability as it was disclosed publicly and has available fixes.