BE-2025-0002: XML parsing vulnerability in MicroStation via libexpat dependency.
Bentley ID: BE-2025-0002
CVE ID: CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-8176
Severity: 7.5
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Publication date: 2025-08-21
Revision date: 2025-08-21
Summary
MicroStation applications may be affected by an XML parsing vulnerability in the libexpat library. The vulnerability occurs when MicroStation uses libexpat for XML processing, where negative length values are not properly rejected in XML_ParseBuffer, potentially leading to denial of service or other security issues.
Details
MicroStation uses libexpat versions prior to 2.6.3 which are affected by improper restriction of XML external entity references (CWE-611) and potential integer overflow (CWE-190).This could potentially allow attackers to cause denial of service or other security impacts when MicroStation processes maliciously crafted XML content through the vulnerable libexpat library.
Affected Versions
| Applications | Affected Versions | Mitigated Versions |
| Bentley MicroStation | < = 2024.0.*.* | = > 2025.0.0.119 |
Recommended Mitigations
Bentley recommends updating to the latest product version. Best practice is to avoid processing files from untrusted sources.
Revision History
| Date | Description |
| 2025-08-21 | Initial advisory for CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-8176 |