Macros Can Run Without Warning Under Microsoft Word
By embedding a macro into a template and providing another user with a Rich Text Format (RTF) document that links to the template, an attacker can cause macros to run automatically when the user opens the RTF document.
May 25, 2001
Reported May 21, 2001, byMicrosoft.
VERSIONS AFFECTED
Microsoft Word 97, 98(J) and 2000
DESCRIPTION
Byembedding a macro into a template and providing another user with a Rich TextFormat (RTF) document that links to the template, an attacker can cause macrosto run automatically when the user opens the RTF document. The macro can takeany action that the user can take (e.g., disabling the user's Word securitysettings, so that in subsequently opened Word documents, Word no longer checksfor macros).
VENDOR RESPONSE
Thevendor, Microsofthas acknowledged this vulnerability and recommends that users immediatelyapply the patch contained in Security Bulletin MS01-028.
CREDIT
Discoveredby Microsoft.
Read more about:
MicrosoftAbout the Author
You May Also Like