QID 91834
Date Published: 2021-11-10
QID 91834: Microsoft 3D Viewer Remote Code Execution (RCE) Vulnerability - November 2021
Microsoft 3D Viewer is prone to Remote Code Execution Vulnerability.
Affected Versions:
Microsoft 3D-Viewer App package versions prior to 7.2107.7012.0
QID Detection Logic (Authenticated):
The detection gets the version of Microsoft.Microsoft3DViewer by querying wmi class Win32_InstalledStoreProgram.
Successful exploitation allows an attacker to execute code remotely.
Solution
Vendor References
- CVE-2021-43208 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43208 - CVE-2021-43209 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43209
CVEs related to QID 91834
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-43208 |
|
||
| CVE-2021-43209 |
|