CVE-2023-2762

Published Jul 12, 2023

Last updated 3 months ago

Overview

Description
A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.
Source
3DS.Information-Security@3ds.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

3DS.Information-Security@3ds.com
CWE-416
nvd@nist.gov
CWE-416

Social media

Hype score
Not currently trending

Configurations