PT-2021-3659 · Autodesk+1 · Autodesk Autocad+1
Published
2021-06-17
·
Updated
2022-05-13
·
CVE-2021-27041
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk AutoCAD (affected versions not specified)
ICONICS GENESIS64 (affected versions not specified)
Description
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This issue can be exploited to execute arbitrary code. The vulnerability is related to the parsing of DWG files, allowing an attacker to potentially execute code remotely by using a specially crafted malicious DWG file.
Recommendations
For Autodesk AutoCAD, update to a version that includes a fix for the DWG file parsing issue.
For ICONICS GENESIS64, update to a version that includes a fix for the DWG file parsing issue.
As a temporary workaround, consider restricting the use of DWG files from untrusted sources to minimize the risk of exploitation.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Autocad
Iconics Genesis64