CVE-2023-36740 is a Remote Code Execution vulnerability affecting Microsoft 3D Viewer. This high-severity flaw (CVSS 7.8) can be exploited with low attack complexity, requiring user interaction (e.g., opening a malicious file) to achieve high impact on confidentiality, integrity, and availability. While not actively exploited in the wild and lacking public exploit code, it garnered attention during Microsoft's September 2023 Patch Tuesday, indicating its significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2306.12012.0CPE matchmatch criteria | cpe:2.3:a:microsoft:3d_viewer:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.2306.12012.0CPE match | cpe:2.3:a:microsoft:3d_viewer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.