CVE-2023-36739 is a Remote Code Execution vulnerability affecting Microsoft 3D Viewer. An attacker could exploit this by tricking a user into opening a specially crafted file, leading to high impact on confidentiality, integrity, and availability. While rated as high severity (CVSS 7.8) and having some media coverage, there is currently no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2307.27042.0CPE matchmatch criteria | cpe:2.3:a:microsoft:3d_viewer:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.2306.12012.0CPE match | cpe:2.3:a:microsoft:3d_viewer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.