ZDI-23-1569: Siemens Solid Edge Viewer FBX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2021-27044.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1569?
ZDI-23-1569 has a critical severity level due to its potential for remote arbitrary code execution.
How do I fix ZDI-23-1569?
To fix ZDI-23-1569, users should update Siemens Solid Edge Viewer to the latest version provided by Siemens.
What are the potential impacts of ZDI-23-1569?
The impacts of ZDI-23-1569 include the risk of remote attackers executing arbitrary code, which may lead to data compromise or system control.
Who is affected by ZDI-23-1569?
Users of all affected versions of Siemens Solid Edge Viewer are at risk from ZDI-23-1569.
Is user interaction required for ZDI-23-1569 exploitation?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file to be exploited.