ZDI-24-611: Luxion KeyShot Viewer X_T File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-611?
The severity of ZDI-24-611 is determined to be critical due to the potential for remote code execution.
How do I fix ZDI-24-611?
To fix ZDI-24-611, ensure that you update to the latest version of Luxion KeyShot Viewer as soon as it is available.
What type of attack vector does ZDI-24-611 use?
ZDI-24-611 allows remote attackers to exploit the vulnerability by tricking users into visiting a malicious page or opening a malicious file.
Is user interaction required for ZDI-24-611 exploitation?
Yes, user interaction is required for ZDI-24-611 exploitation.
Which software is affected by ZDI-24-611?
ZDI-24-611 affects installations of Luxion KeyShot Viewer.