ZDI-24-1096: (0Day) Microsoft Office Visio EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1096?
The severity of ZDI-24-1096 is moderate, as it requires user interaction to exploit.
How do I fix ZDI-24-1096?
To fix ZDI-24-1096, ensure you are using the latest version of Microsoft Office Visio, which includes security updates.
What type of information is exposed by ZDI-24-1096?
ZDI-24-1096 allows attackers to disclose sensitive information from compromised installations of Microsoft Office Visio.
What actions can I take to mitigate ZDI-24-1096?
To mitigate ZDI-24-1096, avoid opening untrusted files or visiting suspicious links that could exploit this vulnerability.
Is user interaction necessary for ZDI-24-1096 to be exploited?
Yes, user interaction is required for ZDI-24-1096 as the target must visit a malicious page or open a malicious file.