CVE-2000-0597

Microsoft Office 2000 Excel and PowerPoint - Arbitrary File Write via VBA SaveAs Function

Title source: llm
STIX 2.1

Description

Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=39589349.ED9DBCAB%40nat.bg
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1399

Scores

EPSS 0.1215
EPSS Percentile 95.8%

Details

Status published
Products (3)
microsoft/excel 2000
microsoft/powerpoint 97
microsoft/powerpoint 2000
Published Jun 27, 2000
Tracked Since Feb 18, 2026