cbcvebase.
CVE-2021-44018
published 2022-02-09

CVE-2021-44018: A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions <…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions < V13.2.0.7), Teamcenter Visualization V13.3 (All versions < V13.3.0.1). The plmxmlAdapterSE70.dll library is vulnerable to memory corruption condition while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15112)

Affected

12 ranges
VendorProductVersion rangeFixed in
siemensjt2go< 13.2.0.713.2.0.7
siemensjt2go
siemenssolid_edge
siemenssolid_edge
siemenssolid_edge_se2021
siemenssolid_edge_se2022
siemensteamcenter_visualization
siemensteamcenter_visualization>= 13.2.0 < 13.2.0.713.2.0.7
siemensteamcenter_visualization>= 13.3.0 < 13.3.0.113.3.0.1
siemensteamcenter_visualization_v13.1
siemensteamcenter_visualization_v13.2
siemensteamcenter_visualization_v13.3