CVE-2021-44433: Use After Free
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains a use after free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14900)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-44433.
What is the severity of CVE-2021-44433?
The severity of CVE-2021-44433 is high with a severity value of 7.8.
What is affected by CVE-2021-44433?
JT Utilities versions prior to V13.1.1.0 and JTTK versions prior to V11.1.1.0 are affected by CVE-2021-44433.
How can the vulnerability be exploited?
The vulnerability can be exploited by parsing specially crafted JT files.
Is there a fix available for CVE-2021-44433?
Yes, Siemens has released a fix for CVE-2021-44433. Please refer to the reference link for more information.