3D Builder Remote Code Execution Vulnerability
CVE-2023-21781
7.8HIGH
Summary
The 3D Builder application by Microsoft has a vulnerability that allows remote code execution, enabling attackers to potentially execute arbitrary code on the user’s machine. This vulnerability can be exploited through specially crafted requests, which may lead to unauthorized actions and compromise system integrity. Users are advised to ensure all application updates are applied to mitigate risk.
Affected Version(s)
3D Builder Unknown 20.0.0 < 20.0.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved