CVE-2023-21782 is a Remote Code Execution vulnerability affecting Microsoft 3D Builder. An attacker could exploit this by tricking a user into opening a malicious file, leading to arbitrary code execution on the victim's system. With a CVSS score of 7.8 (High), this vulnerability requires user interaction and local access for exploitation, but successful attacks could result in high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0.1CPE matchmatch criteria | cpe:2.3:a:microsoft:3d_builder:*:*:*:*:*:*:*:* | ||
>= 20.0.0, < 20.0.1CPE match | cpe:2.3:a:microsoft:3d_builder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.