ZDI-CAN-23124: ZDI-24-611: Luxion KeyShot Viewer X_T File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23124?
The severity of ZDI-CAN-23124 is determined by its CVSS score, which indicates a significant risk due to potential remote code execution.
How do I fix the vulnerability ZDI-CAN-23124?
To mitigate ZDI-CAN-23124, users should update to the latest version of Luxion KeyShot Viewer that includes the security patch.
What types of attacks can exploit ZDI-CAN-23124?
ZDI-CAN-23124 can be exploited through malicious web pages or files that require user interaction to execute arbitrary code.
Is user interaction needed to exploit ZDI-CAN-23124?
Yes, user interaction is required for exploiting ZDI-CAN-23124, as the target must visit a malicious page or open a malicious file.
Which software versions are affected by ZDI-CAN-23124?
ZDI-CAN-23124 affects all installations of Luxion KeyShot Viewer prior to obtaining the necessary security update.