ZDI-CAN-22291: ZDI-24-1094: (0Day) Microsoft Office Visio EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22291?
The severity of ZDI-CAN-22291 has been categorized based on its potential impact on sensitive information disclosure.
How do I fix ZDI-CAN-22291?
To fix ZDI-CAN-22291, ensure that Microsoft Office Visio is updated to the latest version provided by Microsoft.
What is the impact of ZDI-CAN-22291?
The impact of ZDI-CAN-22291 can lead to unauthorized disclosure of sensitive information if exploited.
Is user interaction required to exploit ZDI-CAN-22291?
Yes, user interaction is required for ZDI-CAN-22291, as the user must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-22291?
The affected software for ZDI-CAN-22291 is Microsoft Office Visio.