Out-of-Bounds Read Vulnerability in Bentley Systems MicroStation Connect Software
CVE-2022-41613
7.8HIGH
Key Information:
- Vendor
- Bentley Systems
- Status
- Microstation Connect
- Vendor
- CVE Published:
- 6 January 2023
Summary
Bentley Systems MicroStation Connect versions 10.17.0.209 and earlier are susceptible to an Out-of-Bounds Read vulnerability that occurs during the parsing of DGN files. This flaw may enable an attacker to crash the application, potentially reveal sensitive information, or even execute arbitrary code, posing serious risks to system integrity and security.
Affected Version(s)
MicroStation Connect 0 <= 10.17.0.209
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Michael Heinzl