A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.
References
| Link | Resource |
|---|---|
| http://www.securityfocus.com/bid/100444 | Third Party Advisory VDB Entry |
| https://twitter.com/0x09AL/status/898635999185711108 | |
| https://unity3d.com/security#issues | Patch Vendor Advisory |
| http://www.securityfocus.com/bid/100444 | Third Party Advisory VDB Entry |
| https://twitter.com/0x09AL/status/898635999185711108 | |
| https://unity3d.com/security#issues | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2017-08-18 13:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-12939
Mitre link : CVE-2017-12939
CVE.ORG link : CVE-2017-12939
JSON object : View
Products Affected
microsoft
- windows
unity3d
- unity_editor
CWE
CWE-20
Improper Input Validation
