Remote Code Execution Flaw in Bentley View 10.15.0.75
CVE-2021-46655
7.8HIGH
Summary
A vulnerability in Bentley View 10.15.0.75 enables remote attackers to execute arbitrary code. This flaw occurs during the parsing of JT files, as the software fails to validate the existence of objects before performing operations on them. An attacker can exploit this vulnerability by tricking a user into opening a malicious file or visiting an attacker-controlled page, allowing the execution of unauthorized code in the context of the current process. For further information, please refer to Zebra Initiative advisories.
Affected Version(s)
View 10.15.0.75
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mat Powell of Trend Micro Zero Day Initiative