Macros Can Run Without Warning Under Microsoft Word

By embedding a macro into a template and providing another user with a Rich Text Format (RTF) document that links to the template, an attacker can cause macros to run automatically when the user opens the RTF document.

Ken Pfeil

May 25, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported May 21, 2001, byMicrosoft.

VERSIONS AFFECTED

  • Microsoft Word 97, 98(J) and 2000

DESCRIPTION
Byembedding a macro into a template and providing another user with a Rich TextFormat (RTF) document that links to the template, an attacker can cause macrosto run automatically when the user opens the RTF document. The macro can takeany action that the user can take (e.g., disabling the user's Word securitysettings, so that in subsequently opened Word documents, Word no longer checksfor macros).

 

VENDOR RESPONSE

Thevendor, Microsofthas acknowledged this vulnerability and recommends that users immediatelyapply the patch contained in Security Bulletin MS01-028.

 

CREDIT
Discoveredby Microsoft.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like