CVE-2016-2536
SAP 3D Visual Enterprise Viewer SketchUp document Use-After-Free Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple use-after-free vulnerabilities in SAP 3D Visual Enterprise Viewer allow remote attackers to execute arbitrary code via a crafted SketchUp document. NOTE: the primary affected product may be SketchUp.
Múltiples vulnerabilidaes de uso después de liberación de memoria en SAP 3D Visual Enterprise Viewer permite a atacantes remotos ejecutar código arbitrario a través de un documento SketchUp manipulado. NOTA: el producto principalmente afectado podría ser SketchUp.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of SAP 3D Visual Enterprise Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of SketchUp documents. With a specially crafted SketchUp document, an attacker can force a dangling pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute arbitrary code under the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-02-18 CVE Published
- 2016-02-22 CVE Reserved
- 2024-08-05 CVE Updated
- 2024-10-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/83307 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-16-173 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-16-174 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-16-175 | X_refsource_misc | |
http://www.zerodayinitiative.com/advisories/ZDI-16-176 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | 3d Visual Enterprise Viewer Search vendor "Sap" for product "3d Visual Enterprise Viewer" | * | - |
Affected
| ||||||
Google Search vendor "Google" | Sketchup Search vendor "Google" for product "Sketchup" | * | - |
Affected
|