VulnerabilityModified
CVE-2017-12939
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.
CRITICAL 9.8EPSS 4.73%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.73% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- unity3d/unity editor
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/100444Third Party Advisory, VDB Entry
- https://twitter.com/0x09AL/status/898635999185711108
- https://unity3d.com/security#issuesPatch, Vendor Advisory
- http://www.securityfocus.com/bid/100444Third Party Advisory, VDB Entry
- https://twitter.com/0x09AL/status/898635999185711108
- https://unity3d.com/security#issuesPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.