CVE-2001-0240

Microsoft Word - Unauthenticated Macro Execution via RTF Template Link

Title source: llm
STIX 2.1

Description

Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6571
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2753

Scores

EPSS 0.0143
EPSS Percentile 70.5%

Details

Status published
Products (4)
microsoft/word 97
microsoft/word 98 (2 CPE variants)
microsoft/word 2000
microsoft/word 2001
Published Jun 27, 2001
Tracked Since Feb 18, 2026