CVE-2021-40160

CWE-125Out-of-bounds Read3 documents3 sources
Severity
7.8HIGH
EPSS
0.4%
top 38.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateDec 24

Description

PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages13 packages

NVDautodesk/revit20202020.2.5+2
NVDautodesk/autocad20222022.1.1+1
NVDautodesk/civil_3d20222022.1.1
NVDautodesk/autocad_lt20222022.1.1+1
NVDautodesk/navisworks20192019.6+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3xmw-g98x-jm5w: A maliciously crafted PDF file prior to 92021-12-24
CVEList
CVE-2021-40160: PDFTron prior to 92021-12-23
CVE-2021-40160 (HIGH CVSS 7.8) | PDFTron prior to 9.0.7 version may | cvebase.io