CVE-2001-0240
Microsoft Word - Unauthenticated Macro Execution via RTF Template Link
Title source: llmDescription
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6571
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/2753
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-028
Scores
EPSS
0.0143
EPSS Percentile
70.5%
Details
Status
published
Products (4)
microsoft/word
97
microsoft/word
98 (2 CPE variants)
microsoft/word
2000
microsoft/word
2001
Published
Jun 27, 2001
Tracked Since
Feb 18, 2026