CVE-2023-2762: Use-After-Free vulnerability in SLDPRT file reading procedure affecting SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023
Published Jul 12, 2023
·Updated
A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.
Affected Software
1 affected component
3DS 3dexperience Solidworks>=2021<=2023
Event History
Jul 12, 2023
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-2762.
2
What is the severity of CVE-2023-2762?
The severity of CVE-2023-2762 is high (7 out of 10).
3
Which versions of SOLIDWORKS Desktop are affected by CVE-2023-2762?
SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023 are affected by CVE-2023-2762.
4
How can an attacker exploit CVE-2023-2762?
An attacker can exploit CVE-2023-2762 by opening a specially crafted SLDPRT file, which could allow the execution of arbitrary code.
5
Is there a fix available for CVE-2023-2762?
To fix CVE-2023-2762, it is recommended to update SOLIDWORKS Desktop to a version beyond Release SOLIDWORKS 2023.