Title: Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
Severity: HIGH
Description:
Hazardous ActiveX objects may be executed in Internet Explorer 5.01 through the use of Excel and Powerpoint 2000 and certain OBJECT tags on web pages and HTML messages utilizing IFRAME. An example would be the SaveAs object. It has the capability of saving an Excel or Powerpoint file on any location on a remote system unknowingly to a user, including the start up folder which would force the file to open the next time the user started up windows. If the file was an *.hta file, execution of any application on the system is feasible. Other objects aside from SaveAs may also be exploited with similar methods.
Affected Products:
- Microsoft Excel 2000
- Microsoft Excel 97 0.0.0
- Microsoft Internet Explorer 5.0.1
- Microsoft Office 2000
- Microsoft Office 97 0.0.0
- Microsoft PowerPoint 2000
- Microsoft PowerPoint 97
References:
- Georgi Guninski: IE, Excel 2000, PowerPoint 2000 vulnerability demonstration page (WinNT 4.0)
- Microsoft: Frequently Asked Questions: Microsoft Security Bulletin (MS00-049)
- Paul Rogers: IE5 and Access 2000 vulnerability demonstration page (WinNT 4.0)
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.