ZDI-CAN-22344: ZDI-24-1096: (0Day) Microsoft Office Visio EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office Visio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22344?
The severity of ZDI-CAN-22344 is classified as high due to its potential for sensitive information disclosure.
How do I fix ZDI-CAN-22344?
To mitigate ZDI-CAN-22344, ensure that your Microsoft Office Visio is updated to the latest version provided by Microsoft.
Who is affected by ZDI-CAN-22344?
Users of Microsoft Office Visio are affected by ZDI-CAN-22344 if they open a malicious file or visit a harmful webpage.
What type of attacks exploit ZDI-CAN-22344?
ZDI-CAN-22344 can be exploited through social engineering tactics that require user interaction to disclose sensitive information.
Is user interaction necessary for ZDI-CAN-22344 exploitation?
Yes, user interaction is necessary for ZDI-CAN-22344 exploitation, as the target must either visit a malicious site or open a malicious file.