PT-2021-7086 · Autodesk · Autodesk Autocad+1

Published

2021-11-06

·

Updated

2022-10-07

·

CVE-2022-25797

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk TrueView versions 2021, 2022 Autodesk AutoCAD versions 2019, 2020, 2021, 2022
Description The issue is related to a buffer overflow in memory when parsing DWG or PDF files, which can be exploited by a remote attacker using a specially crafted file to execute arbitrary code in the context of the current user. This can occur due to the application's failure to properly handle crafted files, leading to an unhandled exception.
Recommendations For Autodesk TrueView versions 2021, 2022, update to a version that includes the fix for this issue. For Autodesk AutoCAD versions 2019, 2020, 2021, 2022, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of the DWG and PDF parsing functions until a patch is available. Avoid using the vulnerable software to open or parse untrusted DWG or PDF files until the issue is resolved.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-03255
BDU:2022-03256
CVE-2022-25797

Affected Products

Autodesk Autocad
Autodesk Trueview