CVE-2023-36770 is a remote code execution vulnerability affecting Microsoft 3D Builder. With a CVSS score of 7.8 (High), successful exploitation requires user interaction (UI:R) and could lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) on the affected system. While not actively exploited in the wild (KEV: No) and lacking public exploit code, it was addressed in Microsoft's September 2023 Patch Tuesday, indicating its significance. Community discussion and media coverage are relatively low, but it was mentioned in a BleepingComputer article detailing the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0.4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:3d_builder:*:*:*:*:*:*:*:* | ||
>= 20.0.0, < 20.0.4.0CPE match | cpe:2.3:a:microsoft:3d_builder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.