ZDI-23-1022: Siemens Solid Edge Viewer IFC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1022?
The severity of ZDI-23-1022 is classified as high due to the potential for remote code execution.
How do I fix ZDI-23-1022?
To fix ZDI-23-1022, update Siemens Solid Edge Viewer to the latest version provided by Siemens.
Who can exploit the ZDI-23-1022 vulnerability?
Remote attackers can exploit the ZDI-23-1022 vulnerability, but user interaction is required.
What are the risks associated with ZDI-23-1022?
The risks associated with ZDI-23-1022 include execution of arbitrary code which can lead to system compromise.
Is user interaction necessary for ZDI-23-1022 exploitation?
Yes, user interaction is necessary as targets must visit a malicious page or open a malicious file.