PT-2022-6683 · Autodesk · Autodesk Autocad+1

Published

2022-09-22

·

Updated

2023-04-17

·

CVE-2022-33886

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD versions 2020 through 2023 Autodesk Maya versions 2022 through 2023
Description The issue is related to the incorrect handling of exceptional states in the software, which can be exploited by using specially crafted MODEL and SLDPRT files. This can lead to writing beyond the allocated buffer while parsing through the files, causing an unhandled exception. A malicious actor could leverage this to execute arbitrary code.
Recommendations For Autodesk AutoCAD versions 2020 through 2023, consider disabling the parsing of MODEL and SLDPRT files until a patch is available. For Autodesk Maya versions 2022 through 2023, restrict access to the file parsing functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the vulnerable file parsing functionality in both Autodesk AutoCAD and Maya until the issue is resolved.

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2023-03392
CVE-2022-33886
ZDI-22-1317
ZDI-22-1318
ZDI-23-100

Affected Products

Autodesk Autocad
Autodesk Maya