PT-2021-2169 · Luxion · Luxion Keyshot Viewer+3

Rgod

·

Published

2021-02-04

·

Updated

2021-03-23

·

CVE-2021-22645

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Luxion KeyShot versions prior to 10.1 Luxion KeyShot Viewer versions prior to 10.1 Luxion KeyShot Network Rendering versions prior to 10.1 Luxion KeyVR versions prior to 10.1
Description The issue is related to insufficient warning about dangerous actions in the 3D model rendering software. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information. The .bip documents display a "load" command, which can be pointed to a .dll from a remote network share, allowing the .dll entry point to be executed without sufficient UI warning.
Recommendations For Luxion KeyShot versions prior to 10.1, update to version 10.1 or later to resolve the issue. For Luxion KeyShot Viewer versions prior to 10.1, update to version 10.1 or later to resolve the issue. For Luxion KeyShot Network Rendering versions prior to 10.1, update to version 10.1 or later to resolve the issue. For Luxion KeyVR versions prior to 10.1, update to version 10.1 or later to resolve the issue. As a temporary workaround, consider disabling the "load" command in .bip documents to prevent execution of remote .dll files until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01071
CVE-2021-22645
ZDI-21-323

Affected Products

Luxion Keyshot
Luxion Keyshot Network Rendering
Luxion Keyshot Viewer
Luxion Keyvr