CVE-2000-0891
Description
Default Execution Control List (ECL) in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands via a malicious email attachment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Default Execution Control List (ECL) in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands via a malicious email attachment.
Vulnerability
A default Execution Control List (ECL) in Lotus Notes prior to version 5.02 grants all programs, regardless of authorship, full permissions including access to the file system and ability to execute external code [1]. This permissive configuration allows a malicious program attached to a Notes form (e.g., in an email) to run automatically when the form is opened, without any user prompt [1].
Exploitation
An attacker can craft an email containing a Notes form with a malicious program attached, triggered by an event such as PostOpen [1]. The attacker sends the email to a victim using Lotus Notes. When the victim opens the email, the program executes automatically because the default ECL grants all permissions to any program [1]. No additional user interaction is required beyond opening the email [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands on the victim's workstation with the privileges of the logged-in user [1]. This can lead to complete compromise of the system, including data theft, installation of malware, or further network propagation [1].
Mitigation
The vulnerability is fixed in Lotus Notes version 5.02 [1]. Users should upgrade to 5.02 or later. If upgrading is not possible, administrators should configure ECLs to restrict permissions appropriately, following guidance from IBM/Lotus [1]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.02
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.kb.cert.org/vuls/id/5962nvdExploitPatchThird Party AdvisoryUS Government Resource
- www.notes.net/R5FixList.nsf/Search%21SearchView&Query=CBAT45TU9Snvd
- exchange.xforce.ibmcloud.com/vulnerabilities/5045nvd
News mentions
0No linked articles in our index yet.