PT-2022-18652 · Autodesk · Designreview.Exe

Published

2022-07-29

·

Updated

2022-08-08

·

CVE-2022-27866

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DesignReview.exe (affected versions not specified)
Description The issue arises when a maliciously crafted TIFF file is consumed through the DesignReview.exe application, causing it to read beyond allocated boundaries while parsing the TIFF file. This could potentially lead to code execution in the context of the current process, especially when combined with other vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2022-27866

Affected Products

Designreview.Exe