3D Builder Remote Code Execution Vulnerability
CVE-2023-21783

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 January 2023

Summary

A vulnerability exists in the 3D Builder application that enables remote code execution, allowing an attacker to run arbitrary code on a user's machine. This can lead to a range of malicious activities, including data theft or system compromise. Users of 3D Builder are encouraged to implement security patches as recommended by Microsoft to mitigate potential attacks. For further details, refer to the vendor's advisory.

Affected Version(s)

3D Builder Unknown 20.0.0 < 20.0.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.