PT-2022-25713 · Sap+1 · Sap 3D Visual Enterprise Viewer+1

Published

2022-10-11

·

Updated

2023-07-10

·

CVE-2022-41190

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP 3D Visual Enterprise Viewer version 9
Description The issue arises due to improper memory management. When a manipulated AutoCAD (.dxf) file from untrusted sources is opened in the viewer, it can trigger Remote Code Execution. This occurs when the payload forces a stack-based overflow or reuses a dangling pointer referring to overwritten memory space.
Recommendations For SAP 3D Visual Enterprise Viewer version 9, consider avoiding the use of the TeighaTranslator.exe component when handling .dxf files from untrusted sources until a patch is available. As a temporary workaround, restrict the opening of .dxf files to only those from trusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-41190
ZDI-22-1510
ZDI-22-1517
ZDI-22-1528

Affected Products

Autocad
Sap 3D Visual Enterprise Viewer