CVE-2000-0854
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 37.21% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html
- http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html
- http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.htmlVendor Advisory
- http://www.securityfocus.com/bid/1699Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5263
- http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html
- http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html
- http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.htmlVendor Advisory
- http://www.securityfocus.com/bid/1699Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5263
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.