ZDI-CAN-20167: ZDI-23-572: Microsoft Office Visio DXF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published May 10, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Microsoft Office Visio
Event History
May 10, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20167?
ZDI-CAN-20167 is classified as a medium severity vulnerability.
2
How do I fix ZDI-CAN-20167?
To fix ZDI-CAN-20167, ensure that your Microsoft Office Visio is updated to the latest security patches provided by Microsoft.
3
What type of attack is associated with ZDI-CAN-20167?
ZDI-CAN-20167 is associated with remote information disclosure attacks that require user interaction.
4
Which software is affected by ZDI-CAN-20167?
ZDI-CAN-20167 affects installations of Microsoft Office Visio.
5
Is user interaction necessary to exploit ZDI-CAN-20167?
Yes, user interaction is required as the targeted individual must visit a malicious page or open a malicious file.