VYPR
Unrated severityNVD Advisory· Published Nov 14, 2021· Updated Aug 4, 2024

CVE-2021-43275

CVE-2021-43275

Description

A Use After Free vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free in Open Design Alliance Drawings SDK DGN file reading before 2022.8 allows remote code execution via crafted DGN file.

Vulnerability

A use-after-free vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK versions before 2022.8. The issue arises from the lack of validating the existence of an object prior to performing operations on it, leading to a use-after-free condition when processing specially crafted DGN files. [1]

Exploitation

An attacker can exploit this vulnerability by providing a malicious DGN file to a user or application using the affected SDK. No authentication is required; the victim only needs to open the crafted file. The attacker does not need any special network position beyond delivering the file.

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. This can lead to full compromise of the affected system, including data theft, malware installation, or further lateral movement.

Mitigation

The vulnerability is fixed in Open Design Alliance Drawings SDK version 2022.8, released in November 2021. Users should upgrade to this version or later. No workarounds are documented. The CVE is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.