CVE-2019-7362Uncontrolled Search Path Element in Design Review

Severity
7.8HIGHNVD
EPSS
0.4%
top 41.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 23
Latest updateMay 24

Description

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDautodesk/design_review4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-244q-c67c-j2h7: DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 20182022-05-24
CVEList
CVE-2019-7362: DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 20182019-08-23
CVE-2019-7362 — Uncontrolled Search Path Element | cvebase