QID 92117

Date Published: 2024-02-19

QID 92117: Microsoft 3D Viewer Remote Code Execution (RCE) Vulnerability - February 2024

Microsoft 3D Viewer is prone to Remote Code Execution Vulnerability.

Affected Versions:
Microsoft 3D-Viewer App package versions prior to 7.2401.29012.0

QID Detection Logic (Authenticated):
The detection gets the version of Microsoft.Microsoft3DViewer by querying wmi class Win32_InstalledStoreProgram.

Successful exploitation allows an attacker to execute code remotely.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Users are advised to check CVE-2024-20677

    CVEs related to QID 92117

    Software Advisories
    Advisory ID Software Component Link
    CVE-2024-20677 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20677