High severity7.8NVD Advisory· Published Dec 13, 2022· Updated Jun 17, 2026
CVE-2022-41285
CVE-2022-41285
Description
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains a use-after-free vulnerability that could be triggered while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.
Affected products
9cpe:2.3:a:siemens:jt2go:-:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:jt2go:-:*:*:*:*:*:*:*
- (no CPE)range: < V14.1.0.6
- (no CPE)range: All versions < V14.1.0.6
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*range: >=13.2.0,<13.2.0.12
- (no CPE)range: < V13.2.0.12, < V13.3.0.8, < V14.0.0.4, < V14.1.0.6
- (no CPE)range: All versions < V13.2.0.12
- (no CPE)range: All versions < V13.3.0.8
- (no CPE)range: All versions < V14.0.0.4
- (no CPE)range: All versions < V14.1.0.6
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-700053.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.