CVE-2000-0419 describes a vulnerability in the Office 2000 UA ActiveX Control, which was marked as "safe for scripting" and allowed remote attackers to execute unauthorized activities through the "Show Me" function in Office Help. This flaw impacts a wide range of Microsoft Office 2000 products, including Access, Excel, Word, and PowerPoint. The vulnerability carries a high CVSS score of 7.5, indicating a critical risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:access:2000:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:frontpage:2000:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.