Description
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file).
Published: 2025-11-12
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ucancode
Ucancode e-xd++ Visualization Enterprise Suite
Vendors & Products Ucancode
Ucancode e-xd++ Visualization Enterprise Suite

Wed, 12 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Description UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file).
Title UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE
Weaknesses CWE-823
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ucancode E-xd++ Visualization Enterprise Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-13T16:58:58.184Z

Reserved: 2025-11-12T19:10:31.559Z

Link: CVE-2017-20211

cve-icon Vulnrichment

Updated: 2025-11-13T16:58:52.207Z

cve-icon NVD

Status : Deferred

Published: 2025-11-12T22:15:41.660

Modified: 2026-04-15T00:35:42.020

Link: CVE-2017-20211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-13T15:50:26Z

Weaknesses