CVE-2022-24509: Microsoft Office Visio Remote Code Execution Vulnerability
Published Mar 8, 2022
·Updated
Microsoft Office Visio Remote Code Execution Vulnerability
Affected Software
10 affected componentsFixes available
Microsoft Office 2019 for 32-bit editions
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps
Microsoft Office=2019
Microsoft Office=2021
Microsoft Office Long Term Servicing Channel=2021
Event History
Mar 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Mar 9, 2022
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-24509?
CVE-2022-24509 is rated as critical due to its potential for remote code execution.
2
What types of Microsoft Office products are affected by CVE-2022-24509?
CVE-2022-24509 affects Microsoft Office LTSC 2021, Office 2019, and 365 Apps for Enterprise.
3
How do I fix CVE-2022-24509?
To fix CVE-2022-24509, users should install the latest security updates provided by Microsoft for their affected Office products.
4
What is the impact of exploiting CVE-2022-24509?
Exploitation of CVE-2022-24509 could allow an attacker to execute arbitrary code on the victim's system.
5
Is user interaction required to exploit CVE-2022-24509?
Yes, exploiting CVE-2022-24509 typically requires the user to open a compromised Visio file.