PT-2022-11194 · Autodesk · Autodesk Inventor
Mat Powell
·
Published
2022-01-25
·
Updated
2022-11-16
·
CVE-2021-40159
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk Inventor versions 2019 through 2022
Description
The issue is related to an Information Disclosure vulnerability when parsing JT files, which, in conjunction with other vulnerabilities, may lead to code execution through maliciously crafted JT files in the context of the current process. This could potentially allow for remote code execution.
Recommendations
For Autodesk Inventor versions 2019 through 2022, consider avoiding the use of JT files from untrusted sources until a patch is available.
As a temporary workaround, consider restricting the parsing of JT files to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Inventor