Remote Code Execution Vulnerability in SAP 3D Visual Enterprise Viewer
CVE-2022-41189
7.8HIGH
Summary
A security issue exists in SAP 3D Visual Enterprise Viewer version 9 due to inadequate memory management. When users open a specially crafted AutoCAD (.dwg) file using TeighaTranslator.exe, it can lead to a stack-based overflow or re-use of a dangling pointer. This manipulation may result in the execution of arbitrary code, potentially allowing an attacker to take control of the user's system. Users are advised to ensure files are from trusted sources and monitor updates from SAP for any patches that mitigate this risk.
Affected Version(s)
SAP 3D Visual Enterprise Viewer 9
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved