PatchSiren cyber security CVE debrief
CVE-2022-44696 Microsoft CVE debrief
CVE-2022-44696 is a high-severity remote code execution vulnerability in Microsoft Office Visio. Published by NVD on 2022-12-13 and last modified on 2026-05-19, this vulnerability allows an attacker to execute arbitrary code when a user opens a specially crafted Visio file. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attack vector requiring user interaction, with high impact on confidentiality, integrity, and availability. The vulnerability affects multiple Microsoft Office deployments including Microsoft 365 Apps for Enterprise (x64 and x86), Office 2019 (x64 and x86), and Office LTSC 2021 (x64 and x86). Microsoft has addressed this vulnerability through their security update mechanism. Organizations should apply the available security updates from Microsoft to remediate this vulnerability.
- Vendor
- Microsoft
- Product
- Microsoft Office 2019
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2022-12-13
- Original CVE updated
- 2026-05-19
- Advisory published
- 2022-12-13
- Advisory updated
- 2026-05-19
Who should care
Organizations using Microsoft Office Visio, particularly those in engineering, architecture, and business process documentation roles where Visio files are frequently exchanged externally. Security teams responsible for endpoint protection and patch management should prioritize this vulnerability due to its high severity and common use of Visio in collaborative workflows.
Technical summary
CVE-2022-44696 is a remote code execution vulnerability in Microsoft Office Visio that can be triggered when a user opens a maliciously crafted Visio file. The vulnerability requires user interaction and results in code execution with the privileges of the opening user. Affected products include Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC 2021 across both x64 and x86 architectures. The vulnerability was patched by Microsoft as part of their December 2022 security updates.
Defensive priority
high
Recommended defensive actions
- Apply Microsoft security updates for affected Office and Visio installations
- Prioritize patching systems where Visio files from external sources are regularly processed
- Consider implementing Microsoft Defender Application Control or similar application whitelisting to restrict execution of untrusted Visio content
- Enable Attack Surface Reduction (ASR) rules in Microsoft Defender for Endpoint where available to block Office child process creation
- Train users to avoid opening Visio files from untrusted sources and to verify sender identity before opening unexpected attachments
Evidence notes
Vulnerability details sourced from NVD and Microsoft MSRC. CPE criteria confirm affected product versions. CVSS vector confirms local attack vector with user interaction requirement.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-44696 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-44696
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-44696 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-44696
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-44696
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.