Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Visio Viewer 2010 vulnerabilities could allow remote code execution


Report ID: MS201202008
Date Published: 15 February 2012

Criticality: Important
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Microsoft Visio Viewer 2010




Summary

Five vulnerabilities that are affecting Microsoft Visio Viewer 2010 could each lead to remote code execution.



Detailed Description

Microsoft has issued a security update to address five reported vulnerabilities in Microsoft Visio Viewer 2010, each of which could lead to remote code execution. The vulnerabilities were caused by the way attributes are validated when handling specially crafted Visio files.

These issues have been fixed by correcting the way that Microsoft Visio Viewer validates data when parsing Visio files. Users are recommended to install this latest update to protect against potential exploit.



CVE Reference

CVE-2012-0019
CVE-2012-0020
CVE-2012-0136
CVE-2012-0137
CVE-2012-0138



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-015)




Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.