HTTP: Microsoft Visio Version Number Handling Code Execution Vulnerability

A remote code-execution vulnerability exists in the way An attack targeting this vulnerability can result in the injection and execution of code. If code execution is successful, the behaviour of the target will depend on the intention of the attacker. Any code injected will be executed within the security context of the currently logged in user. In the case of an unsuccessful code execution attack, Microsoft Visio will terminate resulting in the loss of any unsaved data from the current session.

Extended Description

Microsoft Visio is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied data. Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Failed attempts will result in denial-of-service conditions.

Affected Products

Microsoft visio_2003

References

BugTraq: 24349

CVE: CVE-2007-0934

Short Name
HTTP:STC:DL:VISIO-INV-VERSION
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2007-0934 Code Execution Handling Microsoft Number Version Visio Vulnerability bid:24349
Release Date
10/11/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?