SAP security note 2227169, “Potential remote code execution in SAP 3D Visual Enterprise Author, Generator and Viewer”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can potentially exploit SAP 3D Visual Enterprise Author, Generator or Viewer that enables them to take control of the product, including viewing, changing, or deleting data.
Solution
Workaround: The injected code cannot be executed when Data Execution Prevention (DEP) is enabled. All SAP 3D Visual Enterprise products, including Author, Generator, and Viewer, are explicitly marked for DEP, the flag is permanently set, and the user does not have to perform any additional steps to enable it. Protection in all SAP 3D Visual Enterprise products also does not depend on system-wide settings. DEP is available on all modern supported CPUs.
More information about DEP on Windows platform is available at: Microsoft TechNet, Microsoft KB 899298.
Additionally, as a precaution, users should only load models and drawings received from trusted sources.
Please install the required support package.
Reason and prerequisites
A buffer overflow vulnerability exists in shared components used by SAP 3D Visual Enterprise Author, Generator, and Viewer. This enables an attacker to inject code into the working memory that is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the product to terminate.
CVSS
Score 6.8 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected components
- VE_VIEWER_COMPLETE: 8.0 to 8.0
- VE_AUTHOR: 8.0 to 8.0
- VEG: 8.0 to 8.0
Full note on SAP: SAP Support Launchpad note 2227169
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
