Security Advisory
CVE-2001-0628
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.