CVE-2000-0854

Microsoft Office 2000 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0854. PoCs published by Georgi Guninski.

AI-analyzed exploit summary This exploit demonstrates a DLL hijacking vulnerability in Microsoft Windows where a malicious DLL (e.g., riched20.dll) is loaded from the current working directory instead of the system directory. The PoC includes a DLL that displays a message box and executes an arbitrary executable when loaded by an Office application.

Description

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Georgi Guninski · c++localwindows
https://www.exploit-db.com/exploits/20232

This exploit demonstrates a DLL hijacking vulnerability in Microsoft Windows where a malicious DLL (e.g., riched20.dll) is loaded from the current working directory instead of the system directory. The PoC includes a DLL that displays a message box and executes an arbitrary executable when loaded by an Office application.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows (DLL loading mechanism), Microsoft Office applications
No auth needed
Prerequisites: Ability to place a malicious DLL in a directory where an Office document is opened · Victim must open an Office document from the directory containing the malicious DLL
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory mailing-list x_refsource_win2ksec
http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1699
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5263
Third Party Advisory mailing-list x_refsource_ntbugtraq
http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html

Scores

EPSS 0.2970
EPSS Percentile 96.8%

Details

Status published
Products (1)
microsoft/office 2000
Published Nov 14, 2000
Tracked Since Feb 18, 2026