Impact
The vulnerability resides in WIngs3D v.2.4.1. A malformed Wavefront OBJ file can cause the application to crash, resulting in a denial of service. An attacker with local access can supply a crafted file that triggers this failure. The impact is confined to the local system where the application runs and does not provide remote code execution, data compromise, or elevated privileges.
Affected Systems
The affected product is WIngs3D version 2.4.1, with the vendor not publicly identified. Systems running this exact build are susceptible.
Risk and Exploitability
The CVSS score of 5.5 denotes moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating an uncertain or low exploitation likelihood. The attack vector is local, requiring the attacker to create or obtain a malicious OBJ file and open it with the vulnerable application. Successful exploitation would lead to an application crash and a temporary denial of service for users of that instance.
OpenCVE Enrichment