ZDI-CAN-18155: ZDI-23-749: SAP 3D Visual Enterprise Author DST File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SAP 3D Visual Enterprise Author. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18155?
ZDI-CAN-18155 is considered a high-severity vulnerability due to its potential for remote code execution.
What systems are affected by ZDI-CAN-18155?
ZDI-CAN-18155 affects installations of SAP 3D Visual Enterprise Author.
How do I fix ZDI-CAN-18155?
To fix ZDI-CAN-18155, ensure that you install the latest security updates and patches provided by SAP for 3D Visual Enterprise Author.
What kind of attack vector is exploited in ZDI-CAN-18155?
ZDI-CAN-18155 can be exploited through a malicious webpage or by opening a malicious file that requires user interaction.
Who is vulnerable to ZDI-CAN-18155?
Users of SAP 3D Visual Enterprise Author are particularly vulnerable to ZDI-CAN-18155 if they interact with malicious content.