First published: Wed Aug 10 2011(Updated: )
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visio Standard | =2003-sp3 | |
Microsoft Visio Standard | =2007-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1979 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2011-1979, apply the latest security updates provided by Microsoft for Visio 2003 SP3 and 2007 SP2.
CVE-2011-1979 allows attackers to execute arbitrary code on a victim's machine by tricking them into opening a specially crafted Visio file.
CVE-2011-1979 affects Microsoft Visio 2003 SP3 and 2007 SP2.
To mitigate the risks of CVE-2011-1979, ensure that you do not open documents from untrusted sources and keep your software up to date.