PT-2022-25707 · Sap · Sap 3D Visual Enterprise Author

Published

2022-10-11

·

Updated

2023-07-10

·

CVE-2022-41184

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP 3D Visual Enterprise Author version 9
Description The issue arises due to improper memory management. When a manipulated Windows Cursor File (.cur, ico.x3d) from untrusted sources is opened in the affected software, it can trigger Remote Code Execution. This occurs when the payload forces a stack-based overflow or reuses a dangling pointer referring to overwritten memory space.
Recommendations For SAP 3D Visual Enterprise Author version 9, avoid opening Windows Cursor Files (.cur, ico.x3d) from untrusted sources until a patch is available. As a temporary workaround, consider restricting the use of the file parsing functionality for .cur and ico.x3d files to minimize the risk of exploitation.

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-41184
ZDI-22-1548

Affected Products

Sap 3D Visual Enterprise Author