Check Point Reference: | SBP-2009-02 |
Date Published: | 10 Feb 2009 |
Severity: | High |
Last Updated: | Thursday 01 January, 2009 |
Source: | Microsoft Security Bulletin MS09-005 |
Industry Reference: | CVE-2009-0095 CVE-2009-0096 CVE-2009-0097 |
Protection Provided by: | |
Who is Vulnerable? | Microsoft Office Visio 2002 SP2 Microsoft Office Visio 2003 SP3 Microsoft Office Visio 2007 SP1 Microsoft Office Visio 2007 Viewer Microsoft Office Visio 2007 Viewer SP1 |
Vulnerability Description | Multiple remote code execution vulnerabilities have been reported in Microsoft Visio. Microsoft Visio is a diagram creation software for Microsoft Windows. A remote attacker can exploit these vulnerabilities via a specially crafted Visio file. Successful exploitation may allow execution of arbitrary code on a vulnerable system. |
Update/Patch Avaliable | Apply patches: Microsoft Security Bulletin MS09-005 |
Vulnerability Details | The vulnerabilities are due to memory corruption and validation errors Microsoft Visio when parsing a crafted document. A remote attacker could trigger these flaws by convincing the victim to open a specially crafted Visio file. Successful exploitation of these issues allows execution of arbitrary code once a malformed Visio file is being loaded on a vulnerable system. |