VYPR
Unrated severityNVD Advisory· Published Feb 18, 2022· Updated Aug 4, 2024

CVE-2021-46627

CVE-2021-46627

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15457.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free vulnerability in Bentley View's DXF parsing allows remote code execution when a user opens a malicious file.

Vulnerability

This vulnerability is a use-after-free flaw in the parsing of DXF files within Bentley View 10.15.0.75 and all versions prior to 10.16.02.* [1][2]. The issue arises because the software does not validate the existence of an object before performing operations on it, leading to a use-after-free condition when processing specially crafted DXF data [1]. The same vulnerability also affects MicroStation versions prior to 10.16.02.* [2].

Exploitation

To exploit this vulnerability, an attacker must convince a user to open a malicious DXF file or visit a malicious page that triggers the parsing [1]. No authentication is required, but user interaction is necessary. The attacker crafts a DXF file containing data that, when parsed, triggers the use-after-free, allowing the attacker to control the program flow [1][2].

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current process [1][2]. This can lead to full compromise of confidentiality, integrity, and availability, as the attacker gains the same privileges as the user running Bentley View [1][2].

Mitigation

Bentley has addressed this vulnerability in version 10.16.02.* and later of both Bentley View and MicroStation [2]. Users should update to the latest versions as soon as possible. As a general best practice, only open DXF files from trusted sources [2]. No workaround is available for unpatched versions.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.