Jump to content
  • entries
    47
  • comments
    3
  • views
    26257

Vissio Security Problem , Visio Document Parsing Vulnerabilities


Ioannis Zontos

670 views

 Share

Severity: Medium
Summary:

· This vulnerability affects: All current versions of Microsoft Visio

· How an attacker exploits it: By enticing one of your users into opening a maliciously crafted Visio document

· Impact: An attacker can execute code, potentially gaining complete control of your users' computers

· What to do: Deploy the appropriate Visio patches as soon as possible, or let Windows Update do it for you

Exposure:

Microsoft Visio is a very popular diagramming application, which many administrators use to create network diagrams. It also ships with some Office packages.

In a security bulletin released yesterday, Microsoft describes two security vulnerabilities that affect all current versions of Visio. The vulnerabilities differ technically, but share the same scope and impact. They both involve flaws in how Visio parses Visio documents. If an attacker can entice one of your users into opening a specially crafted Visio file (such as .vsd, .vdx, .vst, or .vtx), he could exploit either of these flaws to execute code on that user’s computer with that user's  privileges. If your user has administrative privileges, the attacker could gain complete control of their computer.

Solution Path:

Microsoft has released Visio patches to fix this flaw. You should download, test, and deploy the appropriate patches as soon as possible, or let Windows Update do it for you.

· Visio 2003

· Visio 2007

· Visio 2010

· Visio 2010 x64

 Share

0 Comments


Recommended Comments

There are no comments to display.

Guest
Add a comment...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...