CVE-1999-0354
Last modified
CVE-1999-0354 is a vulnerability of currently unknown severity. Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.. EPSS estimates a 5.11% chance of exploitation in the next 30 days.
Description
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 4.0 |
| Microsoft | Internet Explorer | 5.0 |
| Microsoft | Word | 97 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-0354?
How severe is CVE-1999-0354?
How do I fix CVE-1999-0354?
Are you affected by CVE-1999-0354?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
