TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2021-40166

HIGH
7.8

Beschreibung

A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.

CVE Details

CVSS v3.1 Bewertung7.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht10/7/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

autodesk:autocadautodesk:autocad_advance_steelautodesk:autocad_architectureautodesk:autocad_civil_3dautodesk:autocad_electricalautodesk:autocad_ltautodesk:autocad_map_3dautodesk:autocad_mechanicalautodesk:autocad_mepautodesk:autocad_plant_3dautodesk:design_reviewautodesk:dwg_trueviewautodesk:fusionautodesk:infrastructure_parts_editorautodesk:infraworksautodesk:inventorautodesk:navisworksautodesk:revitautodesk:storm_and_sanitary_analysis

Schwachen (CWE)

CWE-416

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.