Untrusted Pointer Dereference in Luxion products - CVE-2021-22649

 

Untrusted Pointer Dereference in Luxion products - CVE-2021-22649

Published: February 8, 2021


Vulnerability identifier: #VU50418
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22649
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to a NULL pointer dereference error when processing project files. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.


Affected software

KeyShot
KeyShot Viewer
KeyVR
KeyShot Network Rendering

How to mitigate CVE-2021-22649

Install updates from vendor's website.

KeyShot - update to 10.1
KeyShot Viewer - update to 10.1
KeyShot Network Rendering - update to 10.1
KeyVR - update to 10.1

External References

Related Security Bulletins