Home→Descriptions→SA41106
| Secunia ID | |
| Release Date |
02 Sep 2010 |
| Criticality | |
| Solution Status |
Unpatched |
| Software |
MicroStation 7.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Bentley Microstation, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the application loading libraries (e.g. mptools.dll, baseman.dll, wintab32.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening HLN or RDL files located on a remote WebDAV or SMB share. Successful exploitation allows execution of arbitrary code. The vulnerability is reported in version 7.1. Other versions may also be affected. |
| Solution |
Do not open untrusted files. |
| Reported by |
Kalyan |
| Original Advisory |
http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0320.html |