CVE-2020-26991: Siemens JT2Go ASM File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing ASM files. This could lead to pointer dereferences of a value obtained from untrusted source. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11899)
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens JT2Go. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ASM files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26991?
CVE-2020-26991 has been classified with a high severity due to potential pointer dereferences that could lead to exploitation.
How do I fix CVE-2020-26991?
To mitigate CVE-2020-26991, update Siemens JT2Go and Teamcenter Visualization to version 13.1.0.2 or later.
Which versions are affected by CVE-2020-26991?
All versions of Siemens JT2Go and Teamcenter Visualization prior to 13.1.0.2 are vulnerable to CVE-2020-26991.
What type of exploit can CVE-2020-26991 lead to?
CVE-2020-26991 may lead to exploitation through improper validation of user-supplied data, potentially allowing for remote code execution.
Who does CVE-2020-26991 impact?
CVE-2020-26991 impacts users of Siemens JT2Go and Teamcenter Visualization who have not upgraded to the latest versions.