PT-2022-21165 · Sap+1 · Sap 3D Visual Enterprise Viewer+1

Published

2022-06-14

·

Updated

2023-05-31

·

CVE-2022-32235

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP 3D Visual Enterprise Viewer (affected versions not specified)
Description The issue occurs when a user opens manipulated AutoCAD (.dwg) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, causing the application to crash and become temporarily unavailable until it is restarted. This happens due to an out-of-bounds write remote code execution vulnerability related to DWG file parsing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-32235
ZDI-23-745

Affected Products

Autocad
Sap 3D Visual Enterprise Viewer