CVE-2015-8572
published 2015-12-15CVE-2015-8572: Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1)…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.75%
88.6th percentile
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | design_review | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.zerodayinitiative.com/advisories/ZDI-15-615http://www.zerodayinitiative.com/advisories/ZDI-15-616http://www.zerodayinitiative.com/advisories/ZDI-15-618http://www.zerodayinitiative.com/advisories/ZDI-15-619http://www.zerodayinitiative.com/advisories/ZDI-15-620https://knowledge.autodesk.com/support/design-review/downloads/caas/downloads/content/autodesk-design-review-2013-hotfix.htmlhttp://www.zerodayinitiative.com/advisories/ZDI-15-615http://www.zerodayinitiative.com/advisories/ZDI-15-616http://www.zerodayinitiative.com/advisories/ZDI-15-618http://www.zerodayinitiative.com/advisories/ZDI-15-619http://www.zerodayinitiative.com/advisories/ZDI-15-620https://knowledge.autodesk.com/support/design-review/downloads/caas/downloads/content/autodesk-design-review-2013-hotfix.html
2015-12-15
Published