← Back to CVEs
CVE-2022-25790
HIGH7.8
Description
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.
CVE Details
CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published4/11/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
autodesk:advance_steelautodesk:autocadautodesk:autocad_architectureautodesk:autocad_electricalautodesk:autocad_ltautodesk:autocad_map_3dautodesk:autocad_mechanicalautodesk:autocad_mepautodesk:autocad_plant_3dautodesk:civil_3dautodesk:navisworks
Weaknesses (CWE)
CWE-787
References
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005(psirt@autodesk.com)
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.