CVE-2011-1979: Input Validation
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1979?
CVE-2011-1979 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2011-1979?
To fix CVE-2011-1979, apply the latest security updates provided by Microsoft for Visio 2003 SP3 and 2007 SP2.
What types of attacks are possible with CVE-2011-1979?
CVE-2011-1979 allows attackers to execute arbitrary code on a victim's machine by tricking them into opening a specially crafted Visio file.
Which versions of Visio are affected by CVE-2011-1979?
CVE-2011-1979 affects Microsoft Visio 2003 SP3 and 2007 SP2.
How can I mitigate the risks associated with CVE-2011-1979?
To mitigate the risks of CVE-2011-1979, ensure that you do not open documents from untrusted sources and keep your software up to date.