cbcvebase.
CVE-2022-27530
published 2022-04-18

CVE-2022-27530: A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow…

PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.82%
52.8th percentile
A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
autodeskadvance_steel>= 2019 < 2019.1.42019.1.4
autodeskadvance_steel>= 2020 < 2020.1.52020.1.5
autodeskadvance_steel>= 2021 < 2021.1.22021.1.2
autodeskadvance_steel>= 2022 < 2022.1.22022.1.2
autodeskautocad>= 2019 < 2019.1.42019.1.4
autodeskautocad>= 2020 < 2020.1.52020.1.5
autodeskautocad>= 2021 < 2021.1.22021.1.2
autodeskautocad>= 2022 < 2022.1.22022.1.2
autodeskautocad>= 2022 < 2022.2.22022.2.2
autodeskautocad_architecture>= 2019 < 2019.1.42019.1.4
autodeskautocad_architecture>= 2020 < 2020.1.52020.1.5
autodeskautocad_architecture>= 2021 < 2021.1.22021.1.2
autodeskautocad_architecture>= 2022 < 2022.1.22022.1.2
autodeskautocad_electrical>= 2019 < 2019.1.42019.1.4
autodeskautocad_electrical>= 2020 < 2020.1.52020.1.5
autodeskautocad_electrical>= 2021 < 2021.1.22021.1.2
autodeskautocad_electrical>= 2022 < 2022.1.22022.1.2
autodeskautocad_lt>= 2019 < 2019.1.42019.1.4
autodeskautocad_lt>= 2020 < 2020.1.52020.1.5
autodeskautocad_lt>= 2021 < 2021.1.22021.1.2
autodeskautocad_lt>= 2022 < 2022.1.22022.1.2
autodeskautocad_lt>= 2022 < 2022.2.22022.2.2
autodeskautocad_map_3d>= 2019 < 2019.1.42019.1.4
autodeskautocad_map_3d>= 2020 < 2020.1.52020.1.5
autodeskautocad_map_3d>= 2021 < 2021.1.22021.1.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.