CVE-2012-0137: Code Injection
Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0137?
CVE-2012-0137 has a severity rating of critical due to its potential to allow remote code execution.
How do I fix CVE-2012-0137?
To fix CVE-2012-0137, update Microsoft Visio Viewer to the latest version following the security updates provided by Microsoft.
What versions of Microsoft Visio Viewer are affected by CVE-2012-0137?
CVE-2012-0137 affects Microsoft Visio Viewer 2010 and Microsoft Visio Viewer 2010 SP1.
Can CVE-2012-0137 be exploited remotely?
Yes, CVE-2012-0137 can be exploited remotely by attackers through specially crafted Visio files.
What symptoms indicate a successful exploitation of CVE-2012-0137?
Symptoms of successful exploitation of CVE-2012-0137 may include unexpected application crashes or unauthorized code execution.