VYPR
Unrated severityNVD Advisory· Published Jan 13, 2022· Updated Aug 4, 2024

CVE-2021-34915

CVE-2021-34915

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14893.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in Bentley View's J2K parsing allows remote code execution via a malicious file.

Vulnerability

The vulnerability exists in Bentley View version 10.15.0.75 and prior versions (before 10.16.02.*) during the parsing of J2K files. A crafted J2K file can trigger a write past the end of an allocated buffer, leading to memory corruption. User interaction is required: the target must open the malicious file or visit a page that triggers the parsing [1][2].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious J2K file and convincing a user to open it (e.g., via email or a malicious webpage). No authentication or special privileges are needed. The out-of-bounds write occurs during parsing, allowing the attacker to overwrite memory and control execution flow [1].

Impact

Successful exploitation enables arbitrary code execution in the context of the current process. This can lead to full compromise of confidentiality, integrity, and availability of the affected system, with the attacker gaining the same privileges as the user running Bentley View [1][2].

Mitigation

Bentley has released mitigated versions: Bentley View 10.16.02.* and later. Users should update to the latest version. As a workaround, only open J2K files from trusted sources until the update is applied [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.