BE-2021-0008: Out-of-bounds and use-after-free vulnerabilities in MicroStation and MicroStation-based applications
Bentley ID: BE-2021-0008
CVE ID: CVE-2021-34882, CVE-2021-34884, CVE-2021-34918, CVE-2021-34919, CVE-2021-46582, CVE-2021-46611, CVE-2021-46632
Severity: 7.8 (High)
CVSS v3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Publication date: 7th December 2021
Revision date: 4th February 2022
MicroStation and MicroStation-based applications may be affected by out-of-bounds or use-after-free vulnerabilities when opening maliciously JP2 files. Exploiting these vulnerabilities could lead to code execution.
The following vulnerabilities related to this advisory were discovered by TrendMicro ZDI: ZDI-CAN-14835, ZDI-CAN-14837, ZDI-CAN-14896, ZDI-CAN-14897, ZDI-CAN-15376, ZDI-CAN-15405, ZDI-CAN-15462.
Using an affected version of MicroStation or MicroStation-based application to open a JP2 file containing maliciously crafted data can trigger an out-of-bounds or use-after-free vulnerability. Exploitation of these vulnerabilities within the parsing of JP2 files could enable an attacker to execute arbitrary code in the context of the current process.
|Applications||Affected Versions||Mitigated Versions|
|MicroStation||Versions prior to 10.16.02.*||10.16.02.* and more recent|
|Bentley View||Versions prior to 10.16.02.*||10.16.02.* and more recent|
Bentley recommends updating to the latest versions of MicroStation and MicroStation-based applications. As a general best practice, it is also recommended to only open JP2 files coming from trusted sources.
Thanks to Mat Powell of Trend Micro Zero Day Initiative for discovering these vulnerabilities.
|7th December 2021||First version of the advisory|
|4th February 2022||Adding new CVE numbers provided by ZDI|