3D Builder Remote Code Execution Vulnerability
CVE-2023-21782

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 January 2023

Summary

A remote code execution vulnerability exists in Microsoft 3D Builder that could allow an attacker to execute arbitrary code on the affected system. This infection may occur when a specially crafted file is opened in the application. Successful exploitation could enable an attacker to take control of the affected system, leading to compromised data and security breaches. Users of Microsoft 3D Builder should ensure they are using the latest version and apply security updates as soon as they are available to protect against this vulnerability.

Affected Version(s)

3D Builder Unknown 20.0.0 < 20.0.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.