Vulnerability record · CVE-2010-1681 · published 6 May 2010
CVE-2010-1681: Microsoft Visio DXF file parsing buffer overflow in VISIODWG.DLL
Microsoft · Visio
VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio contains a memory buffer overflow (CWE-119) triggered by a crafted DXF file. Because Visio is a desktop document viewer, the flaw is user-assisted: the victim must open a malicious DXF file, after which the overflow can corrupt memory and allow code execution in the context of the Visio process.
Description
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with complete impact and has a very high EPSS score, though exploitation requires user-assisted file opening and no KEV listing is present.
What it is
VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio contains a memory buffer overflow (CWE-119) triggered by a crafted DXF file. Because Visio is a desktop document viewer, the flaw is user-assisted: the victim must open a malicious DXF file, after which the overflow can corrupt memory and allow code execution in the context of the Visio process.
Impact
An attacker who gets a crafted DXF file opened can execute arbitrary code with the privileges of the user running Visio, leading to full compromise of confidentiality, integrity and availability on that host.
Attack surface
Reached remotely by delivering a malicious DXF file to a user who opens it in Visio; no authentication is required, but user interaction (opening the file) is necessary. The CVSS 2.0 vector AV:N/AC:H/Au:N/C:C/I:C/A:C reflects network delivery with high attack complexity and no authentication.
Exploitation
Not listed in CISA KEV, but EPSS is 0.67309 (99.268th percentile), indicating a high modeled likelihood of exploitation, and public references include an Exploit-DB entry and a Core Security advisory. No ransomware group usage is documented in the record.
What to do
- Apply the Microsoft patch that updates VISIODWG.DLL to 10.0.6880.4 or later; verify the DLL version after updating.
- Block or restrict opening of untrusted DXF files in Visio, and use file-type allowlisting or email/web gateway filtering for DXF attachments.
- Run Visio with least privilege and consider Protected View or application sandboxing for documents from external sources.
- Educate users not to open DXF files from unknown or unexpected senders.
Detection
- Monitor for Visio processes (VISIO.EXE) loading VISIODWG.DLL and crashing or spawning child processes such as cmd.exe or powershell.exe.
- Hunt for DXF files written to user-writable paths (Downloads, Temp, email attachment caches) shortly before Visio execution.
- Use endpoint detection to alert on anomalous child processes or network connections originating from Visio.
- Check installed VISIODWG.DLL version across endpoints to identify unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1681 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1681), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.