Heap-based Buffer Overflow in Luxion KeyShot Viewer Allows Remote Code Execution
CVE-2025-1045
7.8HIGH
Summary
A buffer overflow vulnerability exists in Luxion KeyShot Viewer due to improper validation of KSP file data. Attackers can exploit this flaw to execute arbitrary code on affected systems, but user interaction is required to trigger the attack by visiting a malicious site or opening a harmful file. This vulnerability emphasizes the risk associated with file handling in applications.
Affected Version(s)
KeyShot Viewer 2024.1_13.0.0.92
References
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved