CVE-2000-0788

Microsoft Access - Remote Code Execution via Mail Merge VBA Script Execution

Title source: llm
STIX 2.1

Description

The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5322
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1566
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/templates/archive.pike?list=1&msg=398EB9CA.27E03A9C%40nat.bg

Scores

EPSS 0.0842
EPSS Percentile 94.5%

Details

Status published
Products (2)
microsoft/access 2000
microsoft/word 2000
Published Oct 20, 2000
Tracked Since Feb 18, 2026