CVE-2000-0854
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 37%
from disclosure to weapon0 days
Published on NVDMay 7
1st PoCSep 18
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20232⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.htmlhttp://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.htmlhttp://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/5263http://www.securityfocus.com/bid/1699