Remote Code Execution Vulnerability in Luxion KeyShot PVS File Parsing
CVE-2025-1047
7.8HIGH
Summary
A vulnerability exists in Luxion KeyShot due to improper initialization of pointers during the parsing of PVS files. This flaw allows remote attackers to execute arbitrary code on compromised installations. Exploitation requires user interaction, as the target must either visit a malicious webpage or open a malicious file. Successful exploitation could lead to unauthorized actions within the affected process context.
Affected Version(s)
KeyShot 2024 13.0.0 Build 92 4.10.171
References
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved