PT-2021-4016 · Autodesk · Autodesk Dwg+1

Published

2021-06-17

·

Updated

2022-05-13

·

CVE-2021-27043

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD (affected versions not specified)
Description The issue is related to an Arbitrary Address Write problem in the Autodesk DWG application, allowing a malicious user to write in unexpected paths. To exploit this, the attacker would need the victim to enable full page heap in the application. Additionally, there is a concern with information disclosure in an error data area when processing DWG files, which could allow an attacker to write arbitrary files. This could potentially lead to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04542
CVE-2021-27043
ZDI-22-470

Affected Products

Autodesk Autocad
Autodesk Dwg