Remote Code Execution Vulnerability in SAP 3D Visual Enterprise Author
CVE-2022-41184
7.8HIGH
Summary
A vulnerability exists in SAP 3D Visual Enterprise Author - version 9, where improper memory management can be exploited. When a user opens a maliciously crafted Windows Cursor File (.cur, .ico.x3d) from untrusted sources, it may lead to a remote code execution scenario. This occurs due to a stack-based overflow or misuse of a dangling pointer, which points to altered memory space, potentially allowing an attacker to execute arbitrary code.
Affected Version(s)
SAP 3D Visual Enterprise Author 9
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved