VulnerabilityModified
CVE-2012-1888
Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
HIGH 9.3EPSS 24.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 24.15% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/visio · microsoft/visio viewer
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/cas/techalerts/TA12-227A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15811
- http://www.us-cert.gov/cas/techalerts/TA12-227A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15811
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.