Remote Code Execution Vulnerability in Luxion KeyShot DAE File Parsing
CVE-2025-2530
7.8HIGH
Summary
The vulnerability involves the Luxion KeyShot product where uninitialized pointers during the parsing of DAE files can lead to remote code execution. Attackers must trick users into opening a malicious file or visiting a compromised webpage. This flaw allows adversaries to execute arbitrary code within the context of the application, potentially leading to unauthorized actions and data compromise.
Affected Version(s)
KeyShot 2024 13.0.0 Build 92 4.10.171
References
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved