CVE-2017-20211
UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that dereferences a user-supplied pointer without sufficient validation. A crafted input may cause the control to dereference an attacker-controlled pointer, enabling remote code execution in the context of the hosting process. The vulnerability requires user interaction (instantiation of the ActiveX control via a web page or a file).
| CWE | CWE-823 |
| Vendor | ucancode.net software |
| Product | e-xd++ visualization enterprise suite |
| Published | Nov 12, 2025 |
| Last Updated | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for ucancode.net software e-xd++ visualization enterprise suite
Be the first to know when new unknown vulnerabilities affecting ucancode.net software e-xd++ visualization enterprise suite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
UCanCode.Net Software / E-XD++ Visualization Enterprise Suite
0
References
Credits
rgod Zero Day Initiative (ZDI)