CVE-2025-1046
CVSS 3.0 Score 7.8 of 10 (high)
Details
Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 416
Summary
CVE-2025-1046 is a remote code execution vulnerability affecting Luxion KeyShot. This issue arises due to a use-after-free flaw in the SKP file parsing process. The lack of object validation allows attackers to execute arbitrary code on affected installations. User interaction is necessary for exploitation, either through visiting a malicious webpage or opening a specially crafted file. This vulnerability, identified as ZDI-CAN-23646, can lead to significant security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.