CVE-1999-0354
Last modified
CVE-1999-0354 is a vulnerability of currently unknown severity. Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.. EPSS estimates a 5.11% chance of exploitation in the next 30 days.
Description
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 4.0 |
| Microsoft | Internet Explorer | 5.0 |
| Microsoft | Word | 97 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-0354?
How severe is CVE-1999-0354?
How do I fix CVE-1999-0354?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 1999
- CVE-1999-0348IIS ASP caching problem releases sensitive information when …
- CVE-1999-0349A buffer overflow in the FTP list (ls) command in IIS allows…
- CVE-1999-0350Race condition in the db_loader program in ClearCase gives l…
- CVE-1999-0351FTP PASV "Pizza Thief" denial of service and unauthorized da…
- CVE-1999-0352ControlIT 4.5 and earlier (aka Remotely Possible) has weak p…
- CVE-1999-0353rpc.pcnfsd in HP gives remote root access by changing the pe…
- CVE-1999-0355Local or remote users can force ControlIT 4.5 to reboot or f…
- CVE-1999-0356ControlIT v4.5 and earlier uses weak encryption to store use…
- CVE-1999-0357Windows 98 and other operating systems allows remote attacke…
- CVE-1999-0358Digital Unix 4.0 has a buffer overflow in the inc program of…
- CVE-1999-0359ptylogin in Unix systems allows users to perform a denial of…
- CVE-1999-0360MS Site Server 2.0 with IIS 4 can allow users to upload cont…
Are you affected by CVE-1999-0354?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
