CVE-2022-33889Out-of-bounds Write in Autocad

Severity
7.8HIGHNVD
EPSS
0.1%
top 80.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 3
Latest updateOct 4

Description

A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages11 packages

NVDautodesk/autocad2023.0.02023.1.1+1
NVDautodesk/autocad_lt2023.0.02023.1.1+1
NVDautodesk/autocad_mep2023.0.02023.1.1+1
NVDautodesk/autocad_map_3d2023.0.02023.1.1+1

🔴Vulnerability Details

2
GHSA
GHSA-3362-fcx9-m9w5: A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the a2022-10-04
CVEList
CVE-2022-33889: A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the a2022-10-03
CVE-2022-33889 — Out-of-bounds Write in Autocad | cvebase