CVE-2011-0093

CWE-94Code Injection3 documents3 sources
Severity
9.3CRITICAL
EPSS
44.0%
top 2.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 10
Latest updateMay 14

Description

ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmicrosoft/visio2002, 2003, 2007+2

🔴Vulnerability Details

2
GHSA
GHSA-p8jh-8r88-35rc: ELEMENTS2022-05-14
CVEList
CVE-2011-0093: ELEMENTS2011-02-10
CVE-2011-0093 (CRITICAL CVSS 9.3) | ELEMENTS.DLL in Microsoft Visio 200 | cvebase.io