Remote Code Execution Vulnerability in Luxion KeyShot DAE File Parsing
CVE-2025-2530

7.8HIGH

Key Information:

Vendor
Luxion
Status
Vendor
CVE Published:
25 March 2025

Summary

The vulnerability involves the Luxion KeyShot product where uninitialized pointers during the parsing of DAE files can lead to remote code execution. Attackers must trick users into opening a malicious file or visiting a compromised webpage. This flaw allows adversaries to execute arbitrary code within the context of the application, potentially leading to unauthorized actions and data compromise.

Affected Version(s)

KeyShot 2024 13.0.0 Build 92 4.10.171

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.