Intrusion Prevention

MS.Visio.DXF.File.Handling.Buffer.Overflow

Description

This indicates an attempt to exploit a Memory Corruption vulnerability in Microsoft Visio.
The vulnerability is caused by an input validation error that occurs in DWGDP.DLL while processing malformed DXF files. It allows remote attackers to crash the vulnerable software or execute arbitrary code via a crafted DXF file.

Affected Products

Microsoft Visio 2010 Service Pack 1
Microsoft Visio Viewer 2010 Service Pack 1

Impact

System Compromise: remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://www.microsoft.com/technet/security/Bulletin/MS12-059.mspx

CVE References

CVE-2012-1888