ZDI-23-1023: Siemens Solid Edge Viewer STP File Parsing Memory Corruption Remote Code Execution Vulnerability
Published Aug 4, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Siemens Solid Edge Viewer
Event History
Aug 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1023?
The severity of ZDI-23-1023 is high due to the potential for arbitrary code execution.
2
How do I fix ZDI-23-1023?
To fix ZDI-23-1023, update Siemens Solid Edge Viewer to the latest version that addresses this vulnerability.
3
What systems are affected by ZDI-23-1023?
ZDI-23-1023 affects installations of Siemens Solid Edge Viewer.
4
What type of attack is ZDI-23-1023 associated with?
ZDI-23-1023 is associated with remote code execution attacks requiring user interaction.
5
What must a user do to be exploited by ZDI-23-1023?
A user must visit a malicious page or open a malicious file to be exploited by ZDI-23-1023.