Data Parsing Vulnerability in KeyShot Software from Datakit
CVE-2021-27496
7.8HIGH
Summary
The vulnerable modules of KeyShot, including CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, and Jt3dReadPsr, lack appropriate input validation when handling PRT files. This flaw allows attackers to manipulate user-supplied data, potentially leading to pointer dereferences and unauthorized code execution in the application's process context. This weakness poses significant security risks for users of affected KeyShot versions.
Affected Version(s)
Datakit Software libraries embedded in Luxion KeyShot software CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved