CVE-2022-35904: Bentley Microstation
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of IFC files could enable an attacker to read information in the context of the current process.
Affected products
- Bentley Microstation: before 10.17.0 (fixed in 10.17.0)
- Bentley View: before 10.17.0 (fixed in 10.17.0)
Published 2022-07-15. Last modified 2026-06-17.