ZDI-CAN-22290: ZDI-24-1093: (0Day) Microsoft Office Visio EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22290?
The severity of ZDI-CAN-22290 is considered moderate due to its requirement for user interaction.
How do I fix ZDI-CAN-22290?
To fix ZDI-CAN-22290, users should ensure that Microsoft Office Visio is updated to the latest version that addresses this vulnerability.
Who is affected by ZDI-CAN-22290?
ZDI-CAN-22290 affects installations of Microsoft Office Visio, specifically where users may inadvertently visit malicious pages or open harmful files.
What type of attack is associated with ZDI-CAN-22290?
ZDI-CAN-22290 is associated with a remote information disclosure attack that relies on social engineering to succeed.
Is user interaction required for ZDI-CAN-22290 exploitation?
Yes, ZDI-CAN-22290 exploitation requires user interaction to either visit a malicious webpage or open a malicious file.