CNCVE编号:CNCVE-20010628 CVE编号:CAN-2001-0628 安全级别:高 漏洞中文描述: Microsoft Word 2000不检查宏中的AutoRecovery(.asd)文件。这可能允许一个本地的攻击者通过Word用户的ID执行任意宏指令。 漏洞英文描述: Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros. This can allow a local attacker to execute arbitrary macros with the user ID of the Word user. 漏洞参考: Reference: MSKB:Q274228 Reference: URL:http://support.microsoft.com/support/kb/articles/Q274/2/28.asp Reference: BID:2760 Reference: URL:http://www.securityfocus.com/bid/2760 Reference: XF:word-asd-macro-execution(6614) Reference: URL:http://xforce 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误