PT-2022-25703 · Sap · Sap 3D Visual Enterprise Author+1

Published

2022-10-11

·

Updated

2023-07-10

·

CVE-2022-41180

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP 3D Visual Enterprise Author version 9
Description The issue is caused by a lack of proper memory management. When a victim opens a manipulated Portable Document Format (.pdf) file received from untrusted sources, it is possible that a Remote Code Execution can be triggered. This occurs when the payload forces a stack-based overflow or a re-use of a dangling pointer, which refers to overwritten space in memory. The PDFPublishing.dll is involved in this process.
Recommendations For SAP 3D Visual Enterprise Author version 9, consider avoiding the use of the PDFPublishing.dll until a patch is available. As a temporary workaround, restrict the opening of .pdf files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-41180
ZDI-22-1579
ZDI-22-1580
ZDI-22-1581
ZDI-22-1582

Affected Products

Pdfpublishing.Dll
Sap 3D Visual Enterprise Author