vendor:
Visio 2016
by:
César Adrián Coronado Llanos
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Visio 2016
Affected Version From: 16.0.4738.1000
Affected Version To: 16.0.4738.1000
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:visio:2016
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Home Single Language x64
2019
Microsoft Visio 2016 (16.0.4738.1000) ‘Log in accounts’ allows go on whit email formed by one thousand A in every of its parts AAA—A@AAA–A.AAA—A
Microsoft Visio 2016 (16.0.4738.1000) is vulnerable to a buffer overflow attack when a user attempts to log in with an email address formed by one thousand A characters in each of its parts. This can be achieved by running the generator.c code, which creates a file called letters.txt containing one thousand A characters. The user then needs to copy the content of the file to the clipboard, open Visio 2016, click on 'Change account or Login', paste the clipboard, type @, paste the clipboard again, type ., paste the clipboard for the last time, click on 'Next' and then click on 'Professional account'. Visio 2016 will not respond and will remain in a white window without sending any message.
Mitigation:
Users should avoid using long email addresses when logging into Microsoft Visio 2016.