PT-2019-18565 · Autodesk · Autodesk Autocad+9
Published
2019-08-23
·
Updated
2019-09-03
·
CVE-2019-7364
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk Advanced Steel versions 2017 through 2020
Autodesk Civil 3D versions 2017 through 2020
Autodesk AutoCAD versions 2017 through 2020
Autodesk AutoCAD LT versions 2017 through 2020
Autodesk AutoCAD Architecture versions 2017 through 2020
Autodesk AutoCAD Electrical versions 2017 through 2020
Autodesk AutoCAD Map 3D versions 2017 through 2020
Autodesk AutoCAD Mechanical versions 2017 through 2020
Autodesk AutoCAD MEP versions 2017 through 2020
Autodesk AutoCAD Plant 3D versions 2017 through 2020
Autodesk AutoCAD P&ID version 2017
Description
The issue is related to a DLL preloading vulnerability. An attacker may trick a user into opening a malicious DWG file, which could leverage this vulnerability and result in code execution.
Recommendations
For Autodesk Advanced Steel versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk Civil 3D versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD LT versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD Architecture versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD Electrical versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD Map 3D versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD Mechanical versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD MEP versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD Plant 3D versions 2017 through 2020, update to a version that includes a fix for the DLL preloading vulnerability.
For Autodesk AutoCAD P&ID version 2017, update to a version that includes a fix for the DLL preloading vulnerability.
As a temporary workaround, consider avoiding the use of untrusted DWG files until a patch is available.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Advance Steel
Autodesk Autocad
Autodesk Autocad Architecture
Autodesk Autocad Electrical
Autodesk Autocad Mep
Autodesk Autocad Map 3D
Autodesk Autocad Mechanical
Autodesk Autocad P&Id
Autodesk Autocad Plant 3D
Autodesk Civil 3D