← Advisories

Microsoft Visio 2010 v14.0.4514.1004 (dwmapi.dll) DLL Hijacking Exploit

High
Advisory ID
ZSL-2010-4959
Release Date
26 August 2010
Vendor
Microsoft Corp. - http://www.microsoft.com
Affected Version
14.0.4514.1004 MSO (14.0.4536.1000)
CVE
N/A
Tested On
Microsoft Windows XP Professional SP3 (English)
Summary

Microsoft Visio is a diagramming program for Microsoft Windows that uses vector graphics to create diagrams.

Description

MS Visio 2010 suffers from a dll hijacking vulnerability that enables the attacker to execute arbitrary code on a local level. The vulnerable extension is .vss thru dwmapi.dll library.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
26.08.2010Initial release
27.08.2010Added reference [1], [2] and [3]