First published: Tue Dec 14 2021(Updated: )
A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14911)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Jt Open Toolkit | <11.0.3.0 | |
Siemens Jt Utilities | <13.0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-44447.
The severity of CVE-2021-44447 is high.
Siemens JT Open Toolkit versions prior to 11.0.3.0 and Siemens JT Utilities versions prior to 13.0.3.0 are affected by CVE-2021-44447.
The CWE ID for this vulnerability is CWE-416.
An attacker can exploit CVE-2021-44447 by leveraging a use-after-free vulnerability in the JTTK library while parsing specially crafted JT files.