CVE-2000-0597
Microsoft Office 2000 Excel and PowerPoint - Arbitrary File Write via VBA SaveAs Function
Title source: llmDescription
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=39589349.ED9DBCAB%40nat.bg
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-049
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1399
Scores
EPSS
0.1215
EPSS Percentile
95.8%
Details
Status
published
Products (3)
microsoft/excel
2000
microsoft/powerpoint
97
microsoft/powerpoint
2000
Published
Jun 27, 2000
Tracked Since
Feb 18, 2026