Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-53356
HistoryJul 14, 2021 - 12:00 a.m.

Siemens Jt2go and Siemens Teamcenter Visualization Remote Code Execution Vulnerability

2021-07-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
siemens ag
germany
remote code execution
vulnerability
jt2go
teamcenter visualization
bmp files
attack
process.

EPSS

0.002

Percentile

64.9%

Siemens Jt2go and Siemens Teamcenter Visualization are both products of Siemens AG, Germany. Siemens Jt2go is a JT file viewer. A remote code execution vulnerability exists in Siemens JT2Go versions prior to 13.2 and Teamcenter Visualization versions prior to 13.2, which stems from a failure of the BMP_Loader.dll library to properly validate user-supplied data before performing further release operations on objects when parsing BMP files. An attacker could use this vulnerability to execute code in the context of the current process.

EPSS

0.002

Percentile

64.9%

Related for CNVD-2021-53356