CVE-2024-43505
Microsoft Office Visio Remote Code Execution Vulnerability
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.75%
- CWE
- CWE-357
- Published
- 2024-10-08
- Last modified
- 2026-08-19
Affected products
- Microsoft Microsoft Office 2019
- Microsoft Microsoft 365 Apps for Enterprise
- Microsoft Microsoft Office LTSC 2021
- Microsoft Microsoft Office LTSC 2024
Weakness type
Related vulnerabilities
- CVE-2025-49585 — XWiki does not require right warnings for XClass definitions
- CVE-2025-49582 — XWiki's required right warnings for macros are incomplete
- CVE-2022-41904 — Element iOS is vulnerable due to missing decoration for events decrypted with untrusted Megolm sessions
- CVE-2025-49587 — XWiki does not require right warnings for notification displayer objects
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2026-47782 — Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v
- CVE-2021-22645 — Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve
- CVE-2019-13521 — A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software versi