VYPR
Unrated severityNVD Advisory· Published Jun 29, 2021· Updated Aug 3, 2024

CVE-2021-31508

CVE-2021-31508

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13306.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack-based buffer overflow in OpenText Brava! Desktop 16.6.3.84 during DXF parsing lets attackers achieve remote code execution via a crafted DXF file or link.

Vulnerability

A stack-based buffer overflow exists in OpenText Brava! Desktop version 16.6.3.84 during the parsing of DXF files [1]. The specific flaw is triggered when the application fails to properly validate the length of user-supplied data, resulting in a write past the end of an allocated buffer on the heap [1]. No special configuration or privilege is required for the vulnerable code path to be reachable; any user opening a DXF file is susceptible.

Exploitation

To exploit the vulnerability, an attacker must craft a malicious DXF file or convince a user to visit a webpage that triggers the file open dialog [1]. The victim must then open the malicious file using Brava! Desktop. No authentication or network credentials are required beyond initial access to the file. The out-of-bounds write occurs as the parser processes specially crafted fields within the DXF data [1].

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current user process [1]. Given the privileges of the logged-in user, this could lead to full compromise of the affected system, including confidentiality, integrity, and availability impacts. The CVSS v3 score is 7.8, classified as High severity [1].

Mitigation

The vendor has not released a fixed version as of the publication date (2021-06-29) [1]. Users should restrict execution of Brava! Desktop to trusted environments and avoid opening DXF files from untrusted sources. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities Catalog as of the reference date. No official workaround has been provided by OpenText [1].

References
  1. ZDI-21-686

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.