CVE-2021-41537: Siemens Solid Edge Viewer OBJ File Parsing Use-After-Free Remote Code Execution Vulnerability
A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13789).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Solid Edgeto a version that resolves this vulnerability.Fixed in SE2021MP8Patch ZDI-CAN-13789
Event History
Frequently Asked Questions
What is CVE-2021-41537?
CVE-2021-41537 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer.
How can this vulnerability be exploited?
To exploit this vulnerability, the target must visit a malicious page or open a malicious file.
What is the severity of CVE-2021-41537?
CVE-2021-41537 has a severity rating of 7.8 (high).
What software is affected by CVE-2021-41537?
Siemens Solid Edge Viewer versions up to and including SE2021 are affected by CVE-2021-41537.
How can I fix CVE-2021-41537?
Update Siemens Solid Edge Viewer to the latest version to fix CVE-2021-41537.