CVE-2010-1681
Description
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Microsoft Visio - 'VISIODWG.dll .DXF' File Handling (MS10-028) (Metasploit)
Microsoft Visio 2002 - '.DXF' Local Stack Overflow
Metasploit modules
References
- http://www.coresecurity.com/content/ms-visio-dxf-buffer-overflow
- http://www.exploit-db.com/exploits/14944
- http://www.securityfocus.com/archive/1/511121/100/0/threaded
- http://www.securityfocus.com/bid/39836
- http://www.securitytracker.com/id?1023938
- http://www.coresecurity.com/content/ms-visio-dxf-buffer-overflow
- http://www.exploit-db.com/exploits/14944
- http://www.securityfocus.com/archive/1/511121/100/0/threaded
- http://www.securityfocus.com/bid/39836
- http://www.securitytracker.com/id?1023938
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.