CVE-2021-22645
Published: Feb 23, 2021
Modified: Aug 3, 2024
Description
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be pointed to a .dll from a remote network share. As a result, the .dll entry point can be executed without sufficient UI warning.
| Vendor | Product | Versions |
|---|---|---|
n/a | Luxion KeyShot | affected versions prior to 10.1 |
n/a | Luxion KeyShot Viewer | affected versions prior to 10.1 |
n/a | Luxion KeyShot Network Rendering | affected versions prior to 10.1 |
n/a | Luxion KeyVR | affected versions prior to 10.1 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now