Severity
7.5HIGHNVD
GHSA5.0
EPSS
0.8%
top 26.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 22
Latest updateMay 17

Description

Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Trojan horse FAS file in the FAS file search path.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-cfvc-f59m-r6fr: Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Tr2022-05-17
GHSA
Incorrect Privilege Assignment in RESTEasy2022-05-14
CVEList
CVE-2014-0818: Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Tr2014-02-22

📋Vendor Advisories

1
Red Hat
RESTEasy: XXE via parameter entities2014-07-23
CVE-2014-0818 — Code Injection in Autodesk Autocad | cvebase