Remote Code Execution Vulnerability in SAP 3D Visual Enterprise Author
CVE-2022-41180
7.8HIGH
Summary
The vulnerability arises from improper memory management in SAP 3D Visual Enterprise Author, specifically within the PDFPublishing.dll component. When a user opens a specially crafted PDF file from an untrusted source, it can lead to a stack-based overflow or enable re-use of a dangling pointer. This mismanagement allows an attacker to execute arbitrary code, compromising the system's integrity and security. Users are advised to avoid opening suspicious PDF files and to apply any available security updates from SAP promptly.
Affected Version(s)
SAP 3D Visual Enterprise Author 9
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved