PT-2021-4016 · Autodesk · Autodesk Dwg+1
Published
2021-06-17
·
Updated
2022-05-13
·
CVE-2021-27043
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk AutoCAD (affected versions not specified)
Description
The issue is related to an Arbitrary Address Write problem in the Autodesk DWG application, allowing a malicious user to write in unexpected paths. To exploit this, the attacker would need the victim to enable full page heap in the application. Additionally, there is a concern with information disclosure in an error data area when processing DWG files, which could allow an attacker to write arbitrary files. This could potentially lead to remote code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autodesk Autocad
Autodesk Dwg