PT-2014-8915 · Autodesk · Autodesk Design Review

Andrea Micalizzi

+1

·

Publicado

2014-12-04

·

Atualizado

2015-12-16

·

CVE-2014-9268

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Autodesk Design Review versions prior to 2013 Hotfix 1
Description The issue allows remote attackers to execute arbitrary code via a crafted DWF file. This is related to the AdView.AdViewer.1 ActiveX control in Autodesk Design Review.
Recommendations For versions prior to 2013 Hotfix 1, update to Autodesk Design Review 2013 Hotfix 1 or later to resolve the issue. As a temporary workaround, consider disabling the AdView.AdViewer.1 ActiveX control until a patch is available. Restrict access to DWF files from untrusted sources to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9268
ZDI-14-402

Produtos afetados

Autodesk Design Review