CVE-2024-43505: Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43505?
CVE-2024-43505 is classified as a critical remote code execution vulnerability in Microsoft Office Visio.
How do I fix CVE-2024-43505?
To fix CVE-2024-43505, install the latest security updates from Microsoft for the affected Office products.
Which versions of Microsoft Office are affected by CVE-2024-43505?
CVE-2024-43505 affects Microsoft 365 Apps, Office 2019, Office LTSC 2021, and Office LTSC 2024 across both 32-bit and 64-bit editions.
What type of exploit is associated with CVE-2024-43505?
CVE-2024-43505 is associated with remote code execution, allowing an attacker to execute malicious code on a victim's machine.
Are there any workarounds for CVE-2024-43505?
While the primary mitigation is to apply the security updates, disabling macros in Office applications can serve as a temporary workaround against exploitation.