CVE-1999-1055
published 1999-12-31CVE-1999-1055: Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL…
high7.5CVSS 3.1
AVNACLAuNCPIPAP
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
VulDB
Microsoft Excel 97 Russian New Year Call privileges management (XFDB-1737 / SBV-4324)
vuldb·2026-04-20·CVSS 7.5
CVE-1999-1055 [HIGH] Microsoft Excel 97 Russian New Year Call privileges management (XFDB-1737 / SBV-4324)
A vulnerability was found in Microsoft Excel 97. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Russian New Year Call Handler. The manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-1999-1055. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-cx75-p9pm-2q97: Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the
ghsa_unreviewed·2022-04-30
CVE-1999-1055 [HIGH] GHSA-cx75-p9pm-2q97: Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Information Loss or Omission
mitre_cwe·CVSS 7.5
[HIGH] CWE-221 Information Loss or Omission
CWE-221: Information Loss or Omission
The product does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Non-Repudiation. Impact: Hide Activities.
Examples:
This code logs suspicious multiple login attempts.
This code only logs failed login attempts when a certain limit is reached. If an attacker knows this limit, they can stop their attack from being discovered by avoiding the limit.
Observed Examples:
CVE-2004-2227: Web browser's filename selection dialog only shows the beginning portion of long filenames, which can trick users into launching executables with dangerous extensions.
CVE-20
CWE
Product UI does not Warn User of Unsafe Actions
mitre_cwe·CVSS 4.6
[MEDIUM] CWE-356 Product UI does not Warn User of Unsafe Actions
CWE-356: Product UI does not Warn User of Unsafe Actions
The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.
Product systems should warn users that a potentially dangerous action may occur if the user proceeds. For example, if the user downloads a file from an unknown source and attempts to execute the file on their machine, then the application's GUI can indicate that the file is unsafe.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Common Consequences:
Scope: Non-Repudiation. Impact: Hide Activities.
Observed Examples:
CVE-1999-1055: Product does not warn user when document contains certain dangerous funct
http://www.securityfocus.com/bid/179https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-018https://exchange.xforce.ibmcloud.com/vulnerabilities/1737http://www.securityfocus.com/bid/179https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-018https://exchange.xforce.ibmcloud.com/vulnerabilities/1737
1999-12-31
Published