MS.Visio.Object.Header.Handling.Code.Execution

description-logoDescription

This indicates an attempt to exploit a memory-corruption vulnerability in Microsoft Visio.
The vulnerability is caused by an error in vislib.dll while processing malformed VST files. It allows remote attackers to crash the vulnerable software or execute arbitrary code via a crafted VST file.

affected-products-logoAffected Products

Microsoft Office XP SP3
Microsoft Office 2003 SP2
Microsoft Office 2003 SP3
2007 Microsoft Office System
2007 Microsoft Office System SP1

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for the suggested workaround:
http://www.microsoft.com/technet/security/Bulletin/ms08-019.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)