ZDI-23-128: Open Design Alliance (ODA) Drawing SDK DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open Design Alliance (ODA) Drawing SDK. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-128?
ZDI-23-128 has been rated as a high-severity vulnerability due to its potential for remote code execution.
How do I fix ZDI-23-128?
To mitigate ZDI-23-128, ensure you update the Open Design Alliance Drawing SDK to the latest version that addresses this vulnerability.
What types of attacks can exploit ZDI-23-128?
ZDI-23-128 can be exploited through scenarios where a user visits a malicious web page or opens a harmful file.
Does ZDI-23-128 require user interaction to be exploited?
Yes, ZDI-23-128 requires user interaction for successful exploitation, as the user must access a malicious resource.
What are the potential impacts of ZDI-23-128?
The impact of ZDI-23-128 can include unauthorized remote code execution, leading to potential system compromise.