Oval Definition:oval:org.mitre.oval:def:16750
Revision Date:2013-07-01Version:9
Title:Vulnerability in Microsoft Visio Could Allow Information Disclosure - MS13-044
Description:Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-1301
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Visio 2003
Microsoft Visio 2007
Microsoft Visio 2010
Definition Synopsis
  • visio 2003/version
  • Check if the version of visio.exe is less than 11.0.8207.0
  • AND Microsoft Office Visio 2003 Service Pack 3 is installed
  • OR visio 2007/version
  • Check if the version of visio.exe is less than 12.0.6676.5000
  • AND Microsoft Office Visio 2007 Service Pack 3 is installed
  • OR visio 2010/version
  • Check if the version of visio.exe is less than 14.0.7100.5000
  • AND Microsoft Visio 2010 SP1 is installed
  • BACK