PT-2021-23792 · Open Design Alliance · Oda Viewer

Mat Powell

·

Published

2021-11-14

·

Updated

2021-12-06

·

CVE-2021-43272

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Design Alliance ODA Viewer versions prior to 2022.11
Description An improper handling of exceptional conditions issue exists in the ODA Viewer sample. When the viewer encounters invalid or malicious DWF files, it continues to process them instead of stopping upon an exception. This allows an attacker to execute code in the context of the current process by leveraging this issue.
Recommendations For versions prior to 2022.11, update to a version 2022.11 or later to resolve the issue. As a temporary workaround, consider restricting the processing of DWF files from untrusted sources until a patch is available.

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43272
ZDI-21-1358
ZDI-21-1360
ZDI-21-1363

Affected Products

Oda Viewer