PT-2007-2375 · Microsoft · Office Visio+1
Published
2007-06-12
·
Updated
2018-10-16
·
CVE-2007-0934
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Visio version 2002
Description:
A remote code execution issue exists in the way Microsoft Visio handles a specially crafted version number in a Visio (.VSD, VSS, or .VST) file. This occurs when Visio does not correctly validate the
version number field when processing the contents of a file. An attacker could exploit this issue by sending a specially crafted file as an e-mail attachment or hosting it on a malicious or compromised Web site.Recommendations:
For Microsoft Visio version 2002, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Visio
Office