PT-2021-23792 · Open Design Alliance · Oda Viewer
Mat Powell
·
Published
2021-11-14
·
Updated
2021-12-06
·
CVE-2021-43272
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open Design Alliance ODA Viewer versions prior to 2022.11
Description
An improper handling of exceptional conditions issue exists in the ODA Viewer sample. When the viewer encounters invalid or malicious DWF files, it continues to process them instead of stopping upon an exception. This allows an attacker to execute code in the context of the current process by leveraging this issue.
Recommendations
For versions prior to 2022.11, update to a version 2022.11 or later to resolve the issue. As a temporary workaround, consider restricting the processing of DWF files from untrusted sources until a patch is available.
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oda Viewer