This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14878.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.bentley.com/en/common-vulnerability-exposure/BE-2021-0009 | Vendor Advisory | 
| https://www.zerodayinitiative.com/advisories/ZDI-21-1494/ | Third Party Advisory VDB Entry | 
| https://www.bentley.com/en/common-vulnerability-exposure/BE-2021-0009 | Vendor Advisory | 
| https://www.zerodayinitiative.com/advisories/ZDI-21-1494/ | Third Party Advisory VDB Entry | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 06:11
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.bentley.com/en/common-vulnerability-exposure/BE-2021-0009 - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-21-1494/ - Third Party Advisory, VDB Entry | 
14 Jan 2022, 21:49
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 6.8
         v3 : 7.8  | 
| CWE | CWE-787 | |
| CPE | cpe:2.3:a:bentley:microstation:*:*:*:*:*:*:*:* cpe:2.3:a:bentley:bentley_view:*:*:*:*:*:*:*:*  | 
|
| References | (MISC) https://www.bentley.com/en/common-vulnerability-exposure/BE-2021-0009 - Vendor Advisory | |
| References | (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-1494/ - Third Party Advisory, VDB Entry | 
13 Jan 2022, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-01-13 22:15
Updated : 2024-11-21 06:11
NVD link : CVE-2021-34905
Mitre link : CVE-2021-34905
CVE.ORG link : CVE-2021-34905
JSON object : View
Products Affected
                bentley
- microstation
 - bentley_view
 
