PT-2021-3513 · Autodesk · Autodesk Design Review

Published

2021-01-29

·

Updated

2022-09-12

·

CVE-2021-27038

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk Design Review versions 2011 through 2018
Description A Type Confusion issue occurs when processing a maliciously crafted PDF file, allowing a malicious actor to execute arbitrary code. The vulnerability is related to errors in data type conversion during PDF file parsing.
Recommendations For Autodesk Design Review versions 2011 through 2018, update to a version that includes a fix for this issue. As a temporary workaround, consider avoiding the processing of PDF files from untrusted sources until a patch is available. Restrict access to the PDF parsing functionality to minimize the risk of exploitation.

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2021-03562
CVE-2021-27038
ZDI-21-1317
ZDI-21-718

Affected Products

Autodesk Design Review