Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Visio vulnerability could allow information disclosure


Report ID: MS201305008
Date Published: 15 May 2013

Criticality: Important
Compromise Type: information-disclosure
Compromise From: remote


Affected Product/Component:

Microsoft Visio 2003
Microsoft Visio 2007
Microsoft Visio 2010




Summary

A vulnerability in Microsoft Visio could lead to information disclosure, where an attacker could be able to read private data from files on a system.



Detailed Description

Microsoft has issued a security update to address an information disclosure vulnerability in Microsoft Visio, which was caused by improper handling of XML external entities. Upon successful exploitation, an attacker could be able to read private data which may be used to further compromised the system.

This issue has been resolved through the latest update by correcting the way of resolving external entities within a file. Users are recommended to install the update to protect their system from possible exploit attempts.



CVE Reference

CVE-2013-1301



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-044)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.