CVE-2025-2530: Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability
Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of dae files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23698.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-CAN-23698 - Compensating control
Since exploitation requires user interaction (target must visit a malicious page or open a malicious file), reduce risk by preventing users from opening untrusted DAE files or visiting untrusted websites.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2530?
CVE-2025-2530 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-2530?
To fix CVE-2025-2530, update Luxion KeyShot to the latest version provided by the vendor.
What type of vulnerability is CVE-2025-2530?
CVE-2025-2530 is a remote code execution vulnerability caused by access to an uninitialized pointer in DAE file parsing.
What are the requirements to exploit CVE-2025-2530?
Exploitation of CVE-2025-2530 requires user interaction, specifically opening a malicious DAE file.
Which product is affected by CVE-2025-2530?
CVE-2025-2530 affects the Luxion KeyShot software.