Microsoft Visio Object Header Remote Code Execution Vulnerability
BID:28555
Info
Microsoft Visio Object Header Remote Code Execution Vulnerability
| Bugtraq ID: | 28555 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1089 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Apr 08 2008 09:28PM |
| Credit: | An anonymous researcher |
| Vulnerable: |
Microsoft Visio 2007 SP1 Microsoft Visio 2007 0 Microsoft Visio 2003 SP3 Microsoft Visio 2003 SP2 Microsoft Visio 2002 SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Visio Object Header Remote Code Execution Vulnerability
Microsoft Visio is prone to a remote code-execution vulnerability because it fails to adequately handle user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Visio is prone to a remote code-execution vulnerability because it fails to adequately handle user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Visio Object Header Remote Code Execution Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Visio Object Header Remote Code Execution Vulnerability
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Visio 2002 SP2
Microsoft Visio 2003 SP3
Microsoft Visio 2007 0
Microsoft Visio 2007 SP1
Microsoft Visio 2003 SP2
Solution:
Microsoft released an advisory and fixes to address this issue. Please see the references for more information.
Microsoft Visio 2002 SP2
-
Microsoft Security Update for Microsoft Visio 2002 (KB947896)
http://www.microsoft.com/downloads/details.aspx?FamilyId=0056a936-def5 -40fa-bcfc-0ab0dd5c3964&displaylang=en
Microsoft Visio 2003 SP3
-
Microsoft Security Update for Microsoft Office Visio 2003 (KB947650)
http://www.microsoft.com/downloads/details.aspx?FamilyId=18af0ce6-99a0 -4471-8d26-9700a8a8e631&displaylang=en
Microsoft Visio 2007 0
-
Microsoft Security Update for Microsoft Office Visio 2007 (KB947590) - English
http://www.microsoft.com/downloads/details.aspx?FamilyId=0510a1bb-b464 -452c-900f-7f4e58ed9c7e&displaylang=en
Microsoft Visio 2007 SP1
-
Microsoft Security Update for Microsoft Office Visio 2007 (KB947590) - English
http://www.microsoft.com/downloads/details.aspx?FamilyId=0510a1bb-b464 -452c-900f-7f4e58ed9c7e&displaylang=en
Microsoft Visio 2003 SP2
-
Microsoft Security Update for Microsoft Office Visio 2003 (KB947650)
http://www.microsoft.com/downloads/details.aspx?FamilyId=18af0ce6-99a0 -4471-8d26-9700a8a8e631&displaylang=en
References
Microsoft Visio Object Header Remote Code Execution Vulnerability
References:
References:
- Visio Homepage (Microsoft)
- Microsoft Security Bulletin MS08-019 (Microsoft)