Microsoft disclosed two remote code execution flaws affecting Microsoft Office Visio, tracked as CVE-2024-43463 and CVE-2025-59226, through its Security Update Guide. Both entries identify Visio as the impacted product and classify the issues as vulnerabilities that could allow code execution if successfully exploited.
The advisories were published as separate Microsoft security update records and provide official tracking for remediation through Microsoft's update process. Organizations using Visio should review the relevant Security Update Guide entries for affected versions, patch availability, and deployment guidance to reduce the risk of compromise through malicious Visio content or related attack vectors.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a Security Update Guide entry for CVE-2025-59226, another remote code execution vulnerability affecting Microsoft Office Visio. The vulnerability entry was published in October 2025.
Microsoft released a Security Update Guide entry for CVE-2024-43463, a remote code execution vulnerability affecting Microsoft Office Visio. The advisory was published on Patch Tuesday in September 2024.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.