QID 91975
Date Published: 2023-02-15
QID 91975: Microsoft 3D Builder Remote Code Execution (RCE) Vulnerability for February 2023
3D Builder is an application to View, Create, and Personalize 3D objects.
Microsoft has released a security update to 3D Builder Application to address a remote code execution vulnerability.
Affected Versions:
3D Builder Version prior to 20.0.3.0
QID Detection Logic:
This QID gets the version of 3D Builder by querying wmi class Win32_InstalledStoreProgram.
An attacker can perform a Remote Code Execution Vulnerability on a vulnerable version of 3D Builder.
Note: Even though the attack vector is local, Microsoft classified this as a Remote Code Execution Vulnerability because an attacker may exploit this through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
- CVE-2023-23377 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23377 - CVE-2023-23390 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23390
CVEs related to QID 91975
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 3D Builder Application |
|