cbcvebase.
CVE-2022-25790
published 2022-04-11

CVE-2022-25790: A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
autodeskadvance_steel>= 2019 < 2019.1.42019.1.4
autodeskadvance_steel>= 2020 < 2020.1.52020.1.5
autodeskadvance_steel>= 2021 < 2021.1.22021.1.2
autodeskadvance_steel>= 2022 < 2022.1.22022.1.2
autodeskautocad>= 2019 < 2019.1.42019.1.4
autodeskautocad>= 2020 < 2020.1.52020.1.5
autodeskautocad>= 2021 < 2021.1.22021.1.2
autodeskautocad>= 2022 < 2022.1.22022.1.2
autodeskautocad>= 2022 < 2022.2.22022.2.2
autodeskautocad_architecture>= 2019 < 2019.1.42019.1.4
autodeskautocad_architecture>= 2020 < 2020.1.52020.1.5
autodeskautocad_architecture>= 2021 < 2021.1.22021.1.2
autodeskautocad_architecture>= 2022 < 2022.1.22022.1.2
autodeskautocad_electrical>= 2019 < 2019.1.42019.1.4
autodeskautocad_electrical>= 2020 < 2020.1.52020.1.5
autodeskautocad_electrical>= 2021 < 2021.1.22021.1.2
autodeskautocad_electrical>= 2022 < 2022.1.22022.1.2
autodeskautocad_lt>= 2019 < 2019.1.42019.1.4
autodeskautocad_lt>= 2020 < 2020.1.52020.1.5
autodeskautocad_lt>= 2021 < 2021.1.22021.1.2
autodeskautocad_lt>= 2022 < 2022.1.22022.1.2
autodeskautocad_map_3d>= 2019 < 2019.1.42019.1.4
autodeskautocad_map_3d>= 2020 < 2020.1.52020.1.5
autodeskautocad_map_3d>= 2021 < 2021.1.22021.1.2
autodeskautocad_map_3d>= 2022 < 2022.1.22022.1.2