PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-44696 Microsoft CVE debrief

CVE-2022-44696 is a high-severity remote code execution vulnerability in Microsoft Office Visio. Published by NVD on 2022-12-13 and last modified on 2026-05-19, this vulnerability allows an attacker to execute arbitrary code when a user opens a specially crafted Visio file. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attack vector requiring user interaction, with high impact on confidentiality, integrity, and availability. The vulnerability affects multiple Microsoft Office deployments including Microsoft 365 Apps for Enterprise (x64 and x86), Office 2019 (x64 and x86), and Office LTSC 2021 (x64 and x86). Microsoft has addressed this vulnerability through their security update mechanism. Organizations should apply the available security updates from Microsoft to remediate this vulnerability.

Vendor
Microsoft
Product
Microsoft Office 2019
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2022-12-13
Original CVE updated
2026-05-19
Advisory published
2022-12-13
Advisory updated
2026-05-19

Who should care

Organizations using Microsoft Office Visio, particularly those in engineering, architecture, and business process documentation roles where Visio files are frequently exchanged externally. Security teams responsible for endpoint protection and patch management should prioritize this vulnerability due to its high severity and common use of Visio in collaborative workflows.

Technical summary

CVE-2022-44696 is a remote code execution vulnerability in Microsoft Office Visio that can be triggered when a user opens a maliciously crafted Visio file. The vulnerability requires user interaction and results in code execution with the privileges of the opening user. Affected products include Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC 2021 across both x64 and x86 architectures. The vulnerability was patched by Microsoft as part of their December 2022 security updates.

Defensive priority

high

Recommended defensive actions

  • Apply Microsoft security updates for affected Office and Visio installations
  • Prioritize patching systems where Visio files from external sources are regularly processed
  • Consider implementing Microsoft Defender Application Control or similar application whitelisting to restrict execution of untrusted Visio content
  • Enable Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint where available to block Office child process creation
  • Train users to avoid opening Visio files from untrusted sources and to verify sender identity before opening unexpected attachments

Evidence notes

Vulnerability details sourced from NVD and Microsoft MSRC. CPE criteria confirm affected product versions. CVSS vector confirms local attack vector with user interaction requirement.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-44696 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-44696

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-44696 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-44696

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.