CVE-2023-39549: Use After Free
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 2). The affected application contains a use-after-free vulnerability that could be triggered while parsing specially crafted DWG file. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-19562)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Solid Edge SE2023 vulnerability?
The vulnerability ID for this Solid Edge SE2023 vulnerability is CVE-2023-39549.
What versions of Solid Edge SE2023 are affected by this vulnerability?
All versions of Solid Edge SE2023 less than V223.0 Update 2 are affected by this vulnerability.
What is the severity of the CVE-2023-39549 vulnerability?
The severity of the CVE-2023-39549 vulnerability is high with a CVSS score of 7.8.
How does the use-after-free vulnerability in Solid Edge SE2023 CVE-2023-39549 work?
The use-after-free vulnerability in Solid Edge SE2023 CVE-2023-39549 can be triggered while parsing specially crafted DWG files, allowing an attacker to execute code in the context of the affected application.
Is there a fix available for the Solid Edge SE2023 CVE-2023-39549 vulnerability?
Yes, Siemens has released an update, V223.0 Update 2, that fixes the Solid Edge SE2023 CVE-2023-39549 vulnerability.