CVE-2021-27488: (0Day) Siemens Solid Edge Viewer CATPart File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Datakit Software libraries CatiaV53dRead, CatiaV63dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing CATPart files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CATPart files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27488?
CVE-2021-27488 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer.
How can an attacker exploit CVE-2021-27488?
An attacker can exploit CVE-2021-27488 by tricking the target into visiting a malicious page or opening a malicious file.
What software is affected by CVE-2021-27488?
Siemens Solid Edge Viewer, Datakit CrossCadWare (up to version 2021.1), and Luxion KeyShot (up to version 10.1) are affected by CVE-2021-27488.
What is the severity of CVE-2021-27488?
CVE-2021-27488 has a severity rating of 7.8 (high).
How can CVE-2021-27488 be fixed?
To fix CVE-2021-27488, users should update their Siemens Solid Edge Viewer, Datakit CrossCadWare, and Luxion KeyShot to the latest versions available.