CVE-2000-0788
published 2000-10-20CVE-2000-0788: The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.42%
94.4th percentile
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | access | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | word | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h974-5hr9-px48: The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an
ghsa_unreviewed·2022-04-30
CVE-2000-0788 [HIGH] GHSA-h974-5hr9-px48: The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.
GHSA
GHSA-jq7r-5rhw-2vvw: The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic
ghsa_unreviewed·2022-04-30·CVSS 10.0
CVE-2002-0619 [CRITICAL] GHSA-jq7r-5rhw-2vvw: The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic
The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/1566http://www.securityfocus.com/templates/archive.pike?list=1&msg=398EB9CA.27E03A9C%40nat.bghttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-071https://exchange.xforce.ibmcloud.com/vulnerabilities/5322http://www.securityfocus.com/bid/1566http://www.securityfocus.com/templates/archive.pike?list=1&msg=398EB9CA.27E03A9C%40nat.bghttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-071https://exchange.xforce.ibmcloud.com/vulnerabilities/5322
2000-10-20
Published