ZDI-CAN-22289: ZDI-24-1092: (0Day) Microsoft Office Visio DXF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22289?
The severity of ZDI-CAN-22289 is classified as important due to the potential for sensitive information disclosure.
How do I fix ZDI-CAN-22289?
To fix ZDI-CAN-22289, ensure that you install the latest security updates for Microsoft Office Visio from Microsoft.
Who is affected by ZDI-CAN-22289?
Users of Microsoft Office Visio are affected by ZDI-CAN-22289 if they open malicious files or visit malicious web pages.
What actions can be taken to mitigate ZDI-CAN-22289?
To mitigate ZDI-CAN-22289, avoid opening untrusted files and visiting unknown websites.
Does ZDI-CAN-22289 require user interaction to exploit?
Yes, ZDI-CAN-22289 requires user interaction as the target must open a malicious file or visit a malicious page.