CVE-2021-21772

HIGH

Lib3mf - Use After Free

Title source: rule
STIX 2.1

Description

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

Exploits (1)

nomisec WRITEUP 1 stars
by 3dluvr · poc
https://github.com/3dluvr/New-lib3mf.dll-for-MeshMixer

Scores

CVSS v3 8.1
EPSS 0.0167
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (5)
3mf/lib3mf 2.0.0
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
Published Mar 10, 2021
Tracked Since Feb 18, 2026