10
CVSSv2

CVE-2000-0854

Published: 14/11/2000 Updated: 10/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an malicious user to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office 2000

Exploits

source: wwwsecurityfocuscom/bid/1699/info When a program executes under Microsoft Windows, it may require additional code stored in DLL library files These files are dynamically located at run time, and loaded if necessary A weakness exists in the algorithm used to locate these files The search algorithm used to locate DLL files speci ...