ZDI-CAN-22326: ZDI-24-1095: (0Day) Microsoft Office Visio DXF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Aug 6, 2024
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
1 affected component
Microsoft Office Visio
Event History
Aug 6, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22326?
ZDI-CAN-22326 is classified as a medium-severity vulnerability.
2
How do I fix ZDI-CAN-22326?
To fix ZDI-CAN-22326, ensure that you apply the latest security patches released by Microsoft for Office Visio.
3
What type of vulnerability is ZDI-CAN-22326?
ZDI-CAN-22326 is a remote information disclosure vulnerability.
4
What software is affected by ZDI-CAN-22326?
ZDI-CAN-22326 affects Microsoft Office Visio installations.
5
Does ZDI-CAN-22326 require user interaction for exploitation?
Yes, exploiting ZDI-CAN-22326 requires the user to visit a malicious page or open a malicious file.