CVE-2021-44447: Use After Free
A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14911)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-44447.
What is the severity of CVE-2021-44447?
The severity of CVE-2021-44447 is high.
Which products are affected by CVE-2021-44447?
Siemens JT Open Toolkit versions prior to 11.0.3.0 and Siemens JT Utilities versions prior to 13.0.3.0 are affected by CVE-2021-44447.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-416.
How can an attacker exploit CVE-2021-44447?
An attacker can exploit CVE-2021-44447 by leveraging a use-after-free vulnerability in the JTTK library while parsing specially crafted JT files.