ZDI-23-157: Open Design Alliance (ODA) Drawing SDK DGN File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open Design Alliance (ODA) Drawing SDK. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-157?
ZDI-23-157 is categorized as a high severity vulnerability due to its ability to allow remote code execution.
How do I fix ZDI-23-157?
To remediate ZDI-23-157, users should update to the latest version of the Open Design Alliance Drawing SDK provided by the vendor.
What are the potential impacts of ZDI-23-157?
The potential impacts of ZDI-23-157 include unauthorized remote code execution leading to system compromise.
What types of user interaction are required to exploit ZDI-23-157?
Exploitation of ZDI-23-157 requires the user to visit a malicious webpage or open a malicious file.
Is ZDI-23-157 specific to certain software versions?
Yes, ZDI-23-157 specifically affects installations of the Open Design Alliance Drawing SDK.