VULNERABILITY INTELLIGENCE
CVE-2011-1979
CVSS score9.3 HIGH
EPSS probability22.20%
CISA KEVNot currently listed
Published2011-08-10
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Description
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
Weakness classification
- CWE-20: Improper Input Validation
Primary references
- secure@microsoft.com — US Government Resource
- secure@microsoft.com
- secure@microsoft.com
- af854a3a-2127-422b-91ae-364da2661108 — US Government Resource
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108