PT-2021-3518 · Autodesk · Autodesk Autocad+1

Published

2021-02-10

·

Updated

2022-05-12

·

CVE-2021-27036

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk Design Review versions 2011 through 2018 Autodesk AutoCAD (affected versions not specified)
Description The issue is related to a buffer overflow in the parsing of various file formats, including PDF, PCX, PICT, RCL, TIF, BMP, and PSD. This can be exploited by a remote attacker using a maliciously crafted file to execute arbitrary code. The vulnerability is caused by writing beyond the allocated buffer while parsing these files.
Recommendations For Autodesk Design Review versions 2011 through 2018, update to a version that includes the fix for this issue. For Autodesk AutoCAD, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of file parsing functions for the affected formats until a patch is available. Avoid using the vulnerable file parsing functionality for PCX, PDF, PICT, RCL, TIF, BMP, and PSD files until the issue is resolved.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03567
CVE-2021-27036
ZDI-21-1138
ZDI-21-1141
ZDI-21-1142
ZDI-21-1143
ZDI-21-715
ZDI-21-725
ZDI-21-733
ZDI-21-735
ZDI-21-743
ZDI-21-744
ZDI-21-745
ZDI-21-746
ZDI-22-456
ZDI-22-457
ZDI-22-458
ZDI-22-462
ZDI-22-479
ZDI-22-482

Affected Products

Autodesk Autocad
Autodesk Design Review