UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE
UCanCode E-XD++ Visualization Suite has a flaw in its ActiveX control that allows attackers to run malicious code on a victim's computer when they open a specially crafted web page or file. The vulnerability occurs because the software doesn't properly validate pointer values before using them.
The TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control exposes a RotateShape method that performs unsafe pointer dereference on user-supplied input without validation. An attacker can craft malicious input to trigger arbitrary pointer dereference, achieving remote code execution in the context of the hosting process; exploitation requires user interaction to instantiate the control via a compromised web page or file.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →