PT-2021-2169 · Luxion · Luxion Keyshot Viewer+3
Rgod
·
Published
2021-02-04
·
Updated
2021-03-23
·
CVE-2021-22645
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Luxion KeyShot versions prior to 10.1
Luxion KeyShot Viewer versions prior to 10.1
Luxion KeyShot Network Rendering versions prior to 10.1
Luxion KeyVR versions prior to 10.1
Description
The issue is related to insufficient warning about dangerous actions in the 3D model rendering software. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information. The .bip documents display a "load" command, which can be pointed to a .dll from a remote network share, allowing the .dll entry point to be executed without sufficient UI warning.
Recommendations
For Luxion KeyShot versions prior to 10.1, update to version 10.1 or later to resolve the issue.
For Luxion KeyShot Viewer versions prior to 10.1, update to version 10.1 or later to resolve the issue.
For Luxion KeyShot Network Rendering versions prior to 10.1, update to version 10.1 or later to resolve the issue.
For Luxion KeyVR versions prior to 10.1, update to version 10.1 or later to resolve the issue.
As a temporary workaround, consider disabling the "load" command in .bip documents to prevent execution of remote .dll files until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luxion Keyshot
Luxion Keyshot Network Rendering
Luxion Keyshot Viewer
Luxion Keyvr