Microsoft Word RTF Template Macro Execution Vulnerability
BID:2753
Info
Microsoft Word RTF Template Macro Execution Vulnerability
| Bugtraq ID: | 2753 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2001 12:00AM |
| Updated: | May 21 2001 12:00AM |
| Credit: | Posted in a Microsoft Security Bulletin MS01-028 on May 21, 2001. |
| Vulnerable: |
Microsoft Word 98 for Mac Microsoft Word 98 Microsoft Word 97 SR2 Microsoft Word 97 SR1 Microsoft Word 97 Microsoft Word 2001 for Mac Microsoft Word 2000 SR1a Microsoft Word 2000 SR1 Microsoft Word 2000 SP2 Microsoft Word 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Word RTF Template Macro Execution Vulnerability
Microsoft Word does not properly check for macros in RTF template documents. If a user accesses an RTF document linking to a RTF based template with embedded macros, the macros could execute with out prompting the user first.
Microsoft Word does not properly check for macros in RTF template documents. If a user accesses an RTF document linking to a RTF based template with embedded macros, the macros could execute with out prompting the user first.
Exploit / POC
Microsoft Word RTF Template Macro Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.