First published: Thu Sep 04 2003(Updated: )
Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | =97-sr2 | |
Microsoft Office Word | =2002-sp1 | |
Microsoft Office Word | =2000 | |
Microsoft Office Word | =2000-sr1a | |
Microsoft Office Word | =97-sr1 | |
Microsoft Office Word | =98 | |
Microsoft Works Suite | =2001 | |
Microsoft Office Word | =97 | |
Microsoft Works Suite | =2002 | |
Microsoft Office Word | =98 | |
Microsoft Office Word | =2002-sp2 | |
Microsoft Office Word | =2000-sp2 | |
Microsoft Office Word | =2000-sp3 | |
Microsoft Works Suite | =2003 | |
Microsoft Office Word | =2000-sr1 | |
Microsoft Office Word | =2002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0664 has a critical severity rating due to its capability to allow arbitrary macro execution without user consent.
To fix CVE-2003-0664, ensure to apply the security updates released by Microsoft relevant to the affected versions of Word and Works.
CVE-2003-0664 affects Microsoft Word versions 97, 2000, 2002, and Microsoft Works versions 2001, 2002, and 2003.
Yes, CVE-2003-0664 can be exploited remotely through malicious documents that a user opens.
Exploiting CVE-2003-0664 can lead to unauthorized execution of macros, potentially compromising the system or data.