peter bassill · operator
$ cve CVE-2000-0854 JSON

CVE-2000-0854 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 37.2% (pctl 98)

Patch early

A public exploit exists.

Description

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS37.21% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2000-11-14
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftoffice

Public exploits

SourceTitleDate
exploit-dbMicrosoft Windows NT 4.0/2000 - DLL Search Path2000-09-18

References

→ the Explorer  ·  watch your stack  ·  NVD