CVE-2000-0597, known as the "Office HTML Script" vulnerability, affects Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97. This flaw allows remote attackers to leverage the "safe for scripting" designation of these applications, enabling them to force Internet Explorer or certain email clients to save files to arbitrary locations on a user's system via the VBA SaveAs function. Rated with a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and requires no authentication, posing a risk of partial confidentiality, integrity, and availability compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:* | ||
97CPE matchmatch criteria | cpe:2.3:a:microsoft:powerpoint:97:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:powerpoint:2000:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.