CVE-2022-42899
HIGHBentley MicroStation < 10.17.01.58 and View < 10.17.01.19 - Out-of-bounds Read/Stack Overflow via SKP Files
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-42899. PoCs published by iamsanjay.
AI-analyzed exploit summary This repository contains a working PoC for CVE-2022-42899, demonstrating RCE via Apache Commons Text's StringSubstitutor by injecting a malicious script expression. The exploit leverages the 'script' prefix to execute arbitrary JavaScript code, leading to command execution.
Description
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues when opening crafted SKP files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
Exploits (1)
This repository contains a working PoC for CVE-2022-42899, demonstrating RCE via Apache Commons Text's StringSubstitutor by injecting a malicious script expression. The exploit leverages the 'script' prefix to execute arbitrary JavaScript code, leading to command execution.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H