Vulnerabilities > CVE-2003-0664 - Unspecified vulnerability in Microsoft Word and Works
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 16 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS03-035.NASL |
description | The remote host is running a version of Microsoft Word that contains a flaw in its handling of macro command execution. An attacker could use this to execute arbitrary code on this host. To succeed, the attacker would have to send a rogue Word file to a user of this computer and have him open it. Then the macros contained in the Word file would bypass the security model of Word and be executed. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11831 |
published | 2003-09-04 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11831 |
title | MS03-035: Word Macros may run automatically (827653) |
code |
|
Oval
accepted | 2016-02-19T10:00:00.000-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:188 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2004-08-25T12:00:00.000-04:00 | ||||||||||||||||||||||||
title | MS Word Macro Security Bypass Vulnerability | ||||||||||||||||||||||||
version | 6 |
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-035
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-035
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A188
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A188