PT-2022-24116 · Siemens · Solid Edge

Published

2022-10-11

·

Updated

2022-10-21

·

CVE-2022-37864

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Solid Edge versions prior to SE2022MP9
Description A vulnerability has been identified in the affected application, which contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process.
Recommendations For versions prior to SE2022MP9, update to SE2022MP9 or later to resolve the issue. As a temporary workaround, consider avoiding the use of specially crafted DWG files until a patch is applied. Restrict access to DWG file parsing functionality to minimize the risk of exploitation.

Fix

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-37864
ZDI-22-1441

Affected Products

Solid Edge