Lucene search

K
cveMicrosoftCVE-2013-0079
HistoryMar 13, 2013 - 12:55 a.m.

CVE-2013-0079

2013-03-1300:55:01
microsoft
web.nvd.nist.gov
109
microsoft
visio viewer
2010
sp1
remote attackers
arbitrary code
visio file
memory allocation
tree object
type confusion
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.898

Percentile

98.8%

Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka “Visio Viewer Tree Object Type Confusion Vulnerability.”

Affected configurations

Nvd
Node
microsoftoffice_filter_packMatch2010sp1x64
OR
microsoftoffice_filter_packMatch2010sp1x86
OR
microsoftvisioMatch2010sp1x64
OR
microsoftvisioMatch2010sp1x86
OR
microsoftvisio_viewerMatch2010sp1x64
OR
microsoftvisio_viewerMatch2010sp1x86
VendorProductVersionCPE
microsoftoffice_filter_pack2010cpe:2.3:a:microsoft:office_filter_pack:2010:sp1:x64:*:*:*:*:*
microsoftoffice_filter_pack2010cpe:2.3:a:microsoft:office_filter_pack:2010:sp1:x86:*:*:*:*:*
microsoftvisio2010cpe:2.3:a:microsoft:visio:2010:sp1:x64:*:*:*:*:*
microsoftvisio2010cpe:2.3:a:microsoft:visio:2010:sp1:x86:*:*:*:*:*
microsoftvisio_viewer2010cpe:2.3:a:microsoft:visio_viewer:2010:sp1:x64:*:*:*:*:*
microsoftvisio_viewer2010cpe:2.3:a:microsoft:visio_viewer:2010:sp1:x86:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.898

Percentile

98.8%