PT-2021-7086 · Autodesk · Autodesk Autocad+1
Published
2021-11-06
·
Updated
2022-10-07
·
CVE-2022-25797
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Autodesk TrueView versions 2021, 2022
Autodesk AutoCAD versions 2019, 2020, 2021, 2022
Description
The issue is related to a buffer overflow in memory when parsing DWG or PDF files, which can be exploited by a remote attacker using a specially crafted file to execute arbitrary code in the context of the current user. This can occur due to the application's failure to properly handle crafted files, leading to an unhandled exception.
Recommendations
For Autodesk TrueView versions 2021, 2022, update to a version that includes the fix for this issue.
For Autodesk AutoCAD versions 2019, 2020, 2021, 2022, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting the use of the DWG and PDF parsing functions until a patch is available.
Avoid using the vulnerable software to open or parse untrusted DWG or PDF files until the issue is resolved.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Autocad
Autodesk Trueview