Untrusted Pointer Dereference in Luxion products - CVE-2021-22649
Published: February 8, 2021
Vulnerability identifier: #VU50418
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22649
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a NULL pointer dereference error when processing project files. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Affected software
KeyShot
KeyShot Viewer
KeyVR
KeyShot Network Rendering
KeyShot Viewer
KeyVR
KeyShot Network Rendering
How to mitigate CVE-2021-22649
Install updates from vendor's website.
KeyShot - update to 10.1
KeyShot Viewer - update to 10.1
KeyShot Network Rendering - update to 10.1
KeyVR - update to 10.1
KeyShot Viewer - update to 10.1
KeyShot Network Rendering - update to 10.1
KeyVR - update to 10.1