Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ucancode
Ucancode e-xd++ Visualization Enterprise Suite |
|
| Vendors & Products |
Ucancode
Ucancode e-xd++ Visualization Enterprise Suite |
Wed, 12 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file). | |
| Title | UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE | |
| Weaknesses | CWE-823 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-13T16:58:58.184Z
Reserved: 2025-11-12T19:10:31.559Z
Link: CVE-2017-20211
Updated: 2025-11-13T16:58:52.207Z
Status : Deferred
Published: 2025-11-12T22:15:41.660
Modified: 2026-04-15T00:35:42.020
Link: CVE-2017-20211
No data.
OpenCVE Enrichment
Updated: 2025-11-13T15:50:26Z