Use-after-free in Drawings SDK - CVE-2021-32944

 

Use-after-free in Drawings SDK - CVE-2021-32944

Published: June 9, 2021 / Updated: February 13, 2023


Vulnerability identifier: #VU53971
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32944
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the DGN file-reading procedure. A remote attacker can trick a victim to open a specially crafted file and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Drawings SDK
Siemens COMOS
Teamcenter Visualization
JT2Go

How to mitigate CVE-2021-32944

Install updates from vendor's website.

Drawings SDK - update to 2022.4
Siemens COMOS - update to 10.4.1
Teamcenter Visualization - update to 13.2.0.2
JT2Go - update to 13.2.0.2

External References

Related Security Bulletins