CVE-2021-27042Improper Handling of Exceptional Conditions in Advance Steel

Severity
7.8HIGHNVD
EPSS
0.4%
top 41.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 24

Description

A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

NVDautodesk/autocad20192019.1.3+3
NVDautodesk/civil_3d20192019.1.3+3
NVDautodesk/autocad_lt20192019.1.3+3
NVDautodesk/autocad_mep20192019.1.3+3
NVDautodesk/advance_steel20192019.1.3+3

🔴Vulnerability Details

2
GHSA
GHSA-pww6-pfx4-8p5c: A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files2022-05-24
CVEList
CVE-2021-27042: A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files2021-06-25
CVE-2021-27042 — Autodesk Advance Steel vulnerability | cvebase