First published: Mon Mar 22 2021(Updated: )
When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP 3D Visual Enterprise Viewer | =9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27596 has been classified as medium severity due to potential application crashes.
To mitigate CVE-2021-27596, avoid opening untrusted or manipulated .3DS files in SAP 3D Visual Enterprise Viewer.
CVE-2021-27596 affects SAP 3D Visual Enterprise Viewer version 9.
Exploitation of CVE-2021-27596 causes SAP 3D Visual Enterprise Viewer to crash, requiring a restart of the application.
As of now, there is no specified patch for CVE-2021-27596, so users should practice safe handling of .3DS files.