CVE-2020-17003: Base3D Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2020-Oct
- Released
- 2020-10-13
- EPSS Score
- 12.49% (percentile: 93.9%)
Description
A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.
An attacker who successfully exploited the vulnerability would gain execution on a victim system.
The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory.
Affected Products (1)
Other
Security Updates (1)
Acknowledgments
rgod working with <a href="https://www.zerodayinitiative.com/">Trend Micro's Zero Day Initiative</a>
Revision History
- 2020-10-13: Information published.