First published: Tue Jun 12 2007(Updated: )
Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2003 | |
Microsoft Visio Professional | =2002-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0936 is rated as a critical vulnerability due to potential remote code execution.
To fix CVE-2007-0936, ensure that you apply all relevant security updates provided by Microsoft for Visio 2002 and Office 2003.
CVE-2007-0936 affects Microsoft Visio 2002 and Microsoft Office 2003.
CVE-2007-0936 can be exploited through user-assisted remote attacks by opening a specially crafted Visio file.
Exploiting CVE-2007-0936 can lead to memory corruption, resulting in arbitrary code execution on the victim's machine.