ZDI-CAN-18492: ZDI-23-345: Bentley View FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18492?
The severity of ZDI-CAN-18492 is categorized as moderate due to the requirement for user interaction to exploit the vulnerability.
How does ZDI-CAN-18492 enable information disclosure?
ZDI-CAN-18492 allows remote attackers to disclose sensitive information by tricking users into visiting a malicious page or opening a malicious file.
What should users of Bentley View do in response to ZDI-CAN-18492?
Users of Bentley View should maintain caution by avoiding suspicious pages and files until a patch or mitigation is released for ZDI-CAN-18492.
Is user interaction required to exploit ZDI-CAN-18492?
Yes, user interaction is necessary for exploiting ZDI-CAN-18492 as targets need to visit a malicious site or open a harmful file.
Can ZDI-CAN-18492 be exploited without user action?
No, ZDI-CAN-18492 cannot be exploited without user action, making it dependent on the target's behavior.