Remote Code Execution Vulnerability in SAP 3D Visual Enterprise Viewer
CVE-2022-41199
7.8HIGH
What is CVE-2022-41199?
A vulnerability exists in SAP 3D Visual Enterprise Viewer due to improper management of memory. An attacker can exploit this weakness by sending a specially crafted Open Inventor File (.iv, vrml.x3d) to a victim. When the victim opens this manipulated file, it may trigger a remote code execution via a stack-based overflow or the reuse of a dangling pointer that references overwritten memory. This can lead to arbitrary code execution on the victim's system, making it imperative to avoid opening untrusted files and apply necessary patches provided by SAP.
Affected Version(s)
SAP 3D Visual Enterprise Viewer 9