First published: Wed Jul 12 2023(Updated: )
A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.
Credit: 3DS.Information-Security@3ds.com
Affected Software | Affected Version | How to fix |
---|---|---|
Solidworks Product Data Management | >=2021<=2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2023-2762.
The severity of CVE-2023-2762 is high (7 out of 10).
SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023 are affected by CVE-2023-2762.
An attacker can exploit CVE-2023-2762 by opening a specially crafted SLDPRT file, which could allow the execution of arbitrary code.
To fix CVE-2023-2762, it is recommended to update SOLIDWORKS Desktop to a version beyond Release SOLIDWORKS 2023.