Remote Code Execution Vulnerability in SAP 3D Visual Enterprise Viewer
CVE-2022-41199

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability exists in SAP 3D Visual Enterprise Viewer due to improper management of memory. An attacker can exploit this weakness by sending a specially crafted Open Inventor File (.iv, vrml.x3d) to a victim. When the victim opens this manipulated file, it may trigger a remote code execution via a stack-based overflow or the reuse of a dangling pointer that references overwritten memory. This can lead to arbitrary code execution on the victim's system, making it imperative to avoid opening untrusted files and apply necessary patches provided by SAP.

Affected Version(s)

SAP 3D Visual Enterprise Viewer 9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.