CVE-2008-1089: Code Injection
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1089?
CVE-2008-1089 has been classified as a critical vulnerability, allowing remote code execution.
How do I fix CVE-2008-1089?
To resolve CVE-2008-1089, it is recommended to apply the latest security updates provided by Microsoft for the affected Office and Visio products.
What products are affected by CVE-2008-1089?
CVE-2008-1089 affects multiple versions of Microsoft Visio including 2002 SP2, 2003 SP1, 2003 SP2, 2003 SP3, and 2007 versions.
How can attackers exploit CVE-2008-1089?
Attackers can exploit CVE-2008-1089 by crafting malicious Visio files that, when opened by a user, execute arbitrary code.
Is user interaction required to exploit CVE-2008-1089?
Yes, exploitation of CVE-2008-1089 requires user interaction to open a specially crafted Visio file.