Out of Bounds Write Vulnerability in JT Utilities and JTTK by Siemens
CVE-2021-44445

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 December 2021

Summary

A vulnerability exists within Siemens JT Utilities and JTTK that involves an out of bounds write past a fixed-length heap-based buffer when processing specially crafted JT files. This flaw can potentially enable attackers to execute arbitrary code, impacting the integrity of the application and possibly leading to unauthorized access or manipulation of sensitive data.

Affected Version(s)

JT Utilities All versions < V13.1.1.0

JTTK All versions < V11.1.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.