ZDI-23-010: Microsoft Office Visio DWG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Jan 18, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Microsoft Office Visio
Event History
Jan 18, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-010?
The severity of ZDI-23-010 is considered high due to its ability to allow remote code execution.
2
How do I fix ZDI-23-010?
To fix ZDI-23-010, apply the latest security updates from Microsoft for Office Visio.
3
What is the impact of ZDI-23-010?
The impact of ZDI-23-010 includes the potential for remote attackers to execute arbitrary code on affected systems.
4
Does ZDI-23-010 require user interaction to be exploited?
Yes, ZDI-23-010 requires user interaction, as the target must visit a malicious page or open a malicious file.
5
Which software is affected by ZDI-23-010?
ZDI-23-010 affects installations of Microsoft Office Visio.