ZDI-23-907: Siemens Solid Edge Viewer DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-907?
The severity of ZDI-23-907 is considered to be moderate, as it requires user interaction to exploit.
How do I fix ZDI-23-907?
To fix ZDI-23-907, users should ensure they have installed the latest security updates from Siemens for Solid Edge Viewer.
What types of attacks are possible with ZDI-23-907?
ZDI-23-907 can lead to the disclosure of sensitive information if a user visits a malicious website or opens a compromised file.
Who is affected by ZDI-23-907?
Any users of Siemens Solid Edge Viewer are potentially affected by ZDI-23-907.
Is user interaction required to exploit ZDI-23-907?
Yes, user interaction is required to exploit ZDI-23-907, as the target must actively engage with malicious content.