#VU57270 Improper Validation of Array Index in Microsoft Office - CVE-2021-40480
Published: October 12, 2021 / Updated: October 14, 2021
Microsoft Office
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper validation of user-supplied data when parsing EMF files in Microsoft Office Visio. A remote attacker can trick the victim to open a specially crafted file, trigger memory corruption and execute arbitrary code on the system.