ZDI-23-345: Bentley View FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Mar 31, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Bentley View
Event History
Mar 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 27, 2025
Advisory Published
via ZDI·05:53 PM
Frequently Asked Questions
1
What is the severity of ZDI-23-345?
The severity of ZDI-23-345 is considered medium due to the requirement of user interaction for exploitation.
2
How do I fix ZDI-23-345?
To fix ZDI-23-345, users should ensure they are using the latest version of Bentley View that addresses this vulnerability.
3
What type of attack does ZDI-23-345 enable?
ZDI-23-345 enables remote attackers to disclose sensitive information through malicious pages or files.
4
Is user interaction required to exploit ZDI-23-345?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.
5
What software is affected by ZDI-23-345?
The affected software for ZDI-23-345 is Bentley View.