First published: Tue Dec 14 2021(Updated: )
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The DL180pdfl.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14974)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <13.2.0.5 | |
Siemens Teamcenter Visualization | <13.2.0.5 | |
Siemens JT2Go | ||
Siemens JT2Go | <13.2.0.5 | 13.2.0.5 |
Siemens Teamcenter Visualization | <13.2.0.5 | 13.2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44001 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Siemens JT2Go.
CVE-2021-44001 can be exploited by visiting a malicious page or opening a malicious file.
Siemens JT2Go versions up to 13.2.0.5 and Siemens Teamcenter Visualization versions up to 13.2.0.5 are affected by CVE-2021-44001.
CVE-2021-44001 has a severity score of 7.8 out of 10.
To fix CVE-2021-44001, update Siemens JT2Go and Siemens Teamcenter Visualization to a version beyond 13.2.0.5.