vendor:
Microsoft Office Visio
by:
Abysssec
9
CVSS
CRITICAL
Stack Overflow
119
CWE
Product Name: Microsoft Office Visio
Affected Version From: Microsoft Office Visio 2002 (xp)
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2010-1681
CPE: a:microsoft:office_visio:2002
Platforms Tested: Windows XP SP3
2010
Microsoft Office Visio DXF File Stack based Overflow
This exploit takes advantage of a stack-based overflow vulnerability in Microsoft Office Visio 2002 (xp) when parsing DXF files. By specially crafting a DXF file, an attacker can overwrite the EIP register and control the execution flow of the program. This exploit includes a modified alphanumeric shellcode that executes the calc.exe program.
Mitigation:
Apply the necessary patches or update to a newer version of Microsoft Office Visio. Do not open DXF files from untrusted sources.