Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2000-0854Uncontrolled Search Path Element in Microsoft Office

Severity
10.0CRITICALNVD
EPSS
28.4%
top 3.46%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 14
Latest updateApr 30

Description

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-3wxj-j5hp-5gfc: When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched202022-04-30

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows NT 4.0/2000 - DLL Search Path2000-09-18

📐Framework References

1
CWE
Uncontrolled Search Path Element
CVE-2000-0854 — Uncontrolled Search Path Element | cvebase