PT-2021-3659 · Autodesk+1 · Autodesk Autocad+1

Published

2021-06-17

·

Updated

2022-05-13

·

CVE-2021-27041

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD (affected versions not specified) ICONICS GENESIS64 (affected versions not specified)
Description A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This issue can be exploited to execute arbitrary code. The vulnerability is related to the parsing of DWG files, allowing an attacker to potentially execute code remotely by using a specially crafted malicious DWG file.
Recommendations For Autodesk AutoCAD, update to a version that includes a fix for the DWG file parsing issue. For ICONICS GENESIS64, update to a version that includes a fix for the DWG file parsing issue. As a temporary workaround, consider restricting the use of DWG files from untrusted sources to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03886
CVE-2021-27041
ZDI-21-1237
ZDI-21-713
ZDI-21-714
ZDI-22-478

Affected Products

Autodesk Autocad
Iconics Genesis64