ZDI-23-129: Open Design Alliance (ODA) Drawing SDK DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open Design Alliance (ODA) Drawing SDK. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-129?
The severity of ZDI-23-129 is critical due to its potential to allow remote code execution.
How do I fix ZDI-23-129?
To fix ZDI-23-129, update to the latest version of the Open Design Alliance Drawing SDK as recommended by the vendor.
Who is affected by ZDI-23-129?
ZDI-23-129 affects installations of the Open Design Alliance Drawing SDK.
What kind of attacks can exploit ZDI-23-129?
ZDI-23-129 can be exploited through remote code execution, requiring user interaction with a malicious page or file.
Is user interaction required to exploit ZDI-23-129?
Yes, user interaction is required to exploit ZDI-23-129, as the target must visit a malicious website or open a harmful file.