PT-2023-21267 · Dassault Systèmes · Solidworks

Mat Powell

·

Published

2023-07-12

·

Updated

2024-09-02

·

CVE-2023-2763

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOLIDWORKS Desktop versions Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023
Description The issue exists in the DWG and DXF file reading procedure, allowing an attacker to execute arbitrary code while opening a specially crafted file. This is due to Use-After-Free, Out-of-bounds Write, and Heap-based Buffer Overflow vulnerabilities.
Recommendations For versions Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023, consider avoiding the use of DWG and DXF file reading procedures until a patch is available. As a temporary workaround, restrict the opening of specially crafted DWG or DXF files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-2763
ZDI-23-908
ZDI-23-910
ZDI-23-911
ZDI-23-912

Affected Products

Solidworks