CVE-2022-2069: Datalogics APDFL library Heap-based Buffer Overflow
The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-2069.
What is the severity of CVE-2022-2069?
The severity of CVE-2022-2069 is high with a score of 7.8.
Which software is affected by CVE-2022-2069?
Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 are affected by CVE-2022-2069.
How can an attacker exploit CVE-2022-2069?
An attacker can exploit CVE-2022-2069 by parsing specially crafted PDF files, which can lead to an out of bounds write past the fixed-length heap-based buffer and allow the execution of code in the current process context.
Are there any references available for CVE-2022-2069?
Yes, you can find more information about CVE-2022-2069 at the following references: [1](https://cert-portal.siemens.com/productcert/pdf/ssa-829738.pdf) and [2](https://www.cisa.gov/uscert/ics/advisories/icsa-22-195-07).