ZDI-23-745: SAP 3D Visual Enterprise Viewer DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SAP 3D Visual Enterprise Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-745?
The severity of ZDI-23-745 is high, as it allows remote attackers to execute arbitrary code.
How do I fix ZDI-23-745?
To fix ZDI-23-745, update to the latest version of SAP 3D Visual Enterprise Viewer as recommended by SAP.
What are the implications of ZDI-23-745?
The implications of ZDI-23-745 include potential unauthorized access and control over affected installations.
Who is affected by ZDI-23-745?
ZDI-23-745 affects users of SAP 3D Visual Enterprise Viewer who visit malicious pages or open harmful files.
Is user interaction required for ZDI-23-745 exploitation?
Yes, user interaction is required to exploit ZDI-23-745, as the target must visit a malicious page or open a malicious file.