TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-40162

HIGH
7.8

Description

A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

Details CVE

Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie10/7/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

autodesk:autocadautodesk:autocad_advance_steelautodesk:autocad_architectureautodesk:autocad_civil_3dautodesk:autocad_electricalautodesk:autocad_ltautodesk:autocad_map_3dautodesk:autocad_mechanicalautodesk:autocad_mepautodesk:autocad_plant_3dautodesk:design_reviewautodesk:dwg_trueviewautodesk:fusionautodesk:infrastructure_parts_editorautodesk:infraworksautodesk:inventorautodesk:navisworksautodesk:revitautodesk:storm_and_sanitary_analysis

Faiblesses (CWE)

CWE-125

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.