CVE-2022-35903: Low severity bentley microstation vulnerability
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a 3DS file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of 3DS files could enable an attacker to read information in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue in Bentley MicroStation and Bentley View?
The vulnerability ID of this issue in Bentley MicroStation and Bentley View is CVE-2022-35903.
What is the severity level of CVE-2022-35903?
The severity level of CVE-2022-35903 is low with a CVSS score of 3.3.
How can this vulnerability be exploited?
This vulnerability can be exploited by opening a 3DS file containing crafted data in an affected version of MicroStation or MicroStation-based application.
Which versions of Bentley MicroStation are affected by this vulnerability?
Versions of Bentley MicroStation up to exclusive version 10.17.0 are affected by this vulnerability.
Is there a fix available for CVE-2022-35903?
Yes, updating to version 10.17.0.x of Bentley MicroStation or Bentley View resolves the vulnerability.