CVE-2021-27033
published 2021-07-09CVE-2021-27033: A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.99%
85.8th percentile
A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | design_review | — | — |
| autodesk | design_review | — | — |
| autodesk | design_review | — | — |
| autodesk | design_review | — | — |
| autodesk | design_review | — | — |
| autodesk | design_review | >= 2018.0.0, 2017.0.0, 2013.0.0, 2012.0.0, 2011.0.0 < 2018.0.0 | 2018.0.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Autodesk Design Review PDF File double free
vuldb·2026-06-20·CVSS 7.8
CVE-2021-27033 [HIGH] Autodesk Design Review PDF File double free
A vulnerability, which was classified as critical, has been found in Autodesk Design Review. The impacted element is an unknown function of the component PDF File Handler. This manipulation causes double free.
This vulnerability is tracked as CVE-2021-27033. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-65m4-497r-hv9h: A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review
ghsa_unreviewed·2022-05-24
CVE-2021-27033 [HIGH] CWE-415 GHSA-65m4-497r-hv9h: A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review
A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.autodesk.com/products/autodesk-access/overviewhttps://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.htmlhttps://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004
2021-07-09
Published