CVE-2021-44016: Siemens JT2Go PAR File Parsing Memory Corruption Remote Code Execution Vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions < V13.2.0.7), Teamcenter Visualization V13.3 (All versions < V13.3.0.1). The plmxmlAdapterSE70.dll library is vulnerable to memory corruption condition while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15110)
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens JT2Go. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PAR files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Siemens JT2Go PAR File Parsing vulnerability?
The vulnerability ID for this Siemens JT2Go PAR File Parsing vulnerability is CVE-2021-44016.
What is the severity of CVE-2021-44016?
The severity of CVE-2021-44016 is high with a CVSS score of 7.8.
Which Siemens products are affected by CVE-2021-44016?
Siemens JT2Go versions prior to V13.2.0.7, Solid Edge SE2021 versions prior to SE2021MP9, Solid Edge SE2022 versions prior to SE2022MP1, Teamcenter Visualization V13.1 versions prior to V13.1.0.9, and Teamcenter Visualization V13.2 versions prior to V13.2.0.7 are affected by CVE-2021-44016.
How can I fix CVE-2021-44016?
To fix CVE-2021-44016, users should update to the following versions or higher: JT2Go V13.2.0.7, Solid Edge SE2021MP9, Solid Edge SE2022MP1, Teamcenter Visualization V13.1.0.9, and Teamcenter Visualization V13.2.0.7.
Are there any additional references for CVE-2021-44016?
Yes, additional references for CVE-2021-44016 can be found at the following links: [SSA-301589](https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf) and [ZDI-22-338](https://www.zerodayinitiative.com/advisories/ZDI-22-338/).