CVE-1999-1055

Microsoft Excel 97 - Code Injection

Title source: llm
STIX 2.1

Description

Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1737
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/179

Scores

EPSS 0.0688
EPSS Percentile 93.4%

Details

Status published
Products (1)
microsoft/excel 97
Published Dec 31, 1999
Tracked Since Feb 18, 2026