Remote Code Execution Flaw in Bentley View 10.15.0.75
CVE-2021-46655

7.8HIGH

Key Information:

Vendor
Bentley
Status
Vendor
CVE Published:
18 February 2022

Summary

A vulnerability in Bentley View 10.15.0.75 enables remote attackers to execute arbitrary code. This flaw occurs during the parsing of JT files, as the software fails to validate the existence of objects before performing operations on them. An attacker can exploit this vulnerability by tricking a user into opening a malicious file or visiting an attacker-controlled page, allowing the execution of unauthorized code in the context of the current process. For further information, please refer to Zebra Initiative advisories.

Affected Version(s)

View 10.15.0.75

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mat Powell of Trend Micro Zero Day Initiative
.