PT-2022-18655 · Autodesk · Autodesk Autocad
Published
2022-06-21
·
Updated
2022-06-29
·
CVE-2022-27869
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk AutoCAD version 2023
Description
A maliciously crafted TIFF file can force the software to read and write beyond allocated boundaries when parsing the TIFF file, potentially allowing the execution of arbitrary code.
Recommendations
For Autodesk AutoCAD version 2023, update to a version that includes a fix for this issue, as the current version can be exploited to execute arbitrary code. As a temporary workaround, consider avoiding the use of maliciously crafted TIFF files until a patch is available.
Fix
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autodesk Autocad