Autodesk Autocad vulnerabilities
171 known vulnerabilities affecting autodesk/autocad.
Total CVEs
171
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH162MEDIUM4LOW1
Vulnerabilities
Page 9 of 9
CVE-2021-27043P3HIGHCVSS 7.8≥ 2019, < 2019.1.3≥ 2020, < 2020.1.4+2 more2021-06-25
CVE-2021-27043 [HIGH] CWE-787 CVE-2021-27043: An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to lever
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.
nvd
CVE-2022-27530P3HIGHCVSS 7.8≥ 2019, < 2019.1.4≥ 2020, < 2020.1.5+3 more2022-04-18
CVE-2022-27530 [HIGH] CWE-787 CVE-2022-27530: A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to wri
A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code.
nvd
CVE-2022-25791P3HIGHCVSS 7.8≥ 2019, < 2019.1.4≥ 2020, < 2020.1.5+3 more2022-04-11
CVE-2022-25791 [HIGH] CWE-787 CVE-2022-25791: A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019
A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.
nvd
CVE-2022-33881P3HIGHCVSS 7.8v20232022-07-29
CVE-2022-33881 [HIGH] CWE-125 CVE-2022-33881: Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boun
Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
nvd
CVE-2022-33887P3HIGHCVSS 7.8≥ 2022, < 2022.1.3≥ 2023, < 2023.1.12022-10-03
CVE-2022-33887 [HIGH] CWE-755 CVE-2022-33887: A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled excepti
A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.
nvd
CVE-2022-33889P3HIGHCVSS 7.8fixed in 2022.1.3≥ 2023.0.0, < 2023.1.12022-10-03
CVE-2022-33889 [HIGH] CWE-787 CVE-2022-33889: A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.
nvd
CVE-2023-25003P3HIGHCVSS 7.8≥ 2020, < 2020.1.6≥ 2021, < 2021.1.3+2 more2023-06-23
CVE-2023-25003 [HIGH] CWE-125 CVE-2023-25003: A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigge
A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.
nvd
CVE-2023-25004P4HIGHCVSS 7.8≥ 2020, < 2020.1.6≥ 2021, < 2021.1.3+2 more2023-06-27
CVE-2023-25004 [HIGH] CWE-190 CVE-2023-25004: A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vul
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
nvd
CVE-2021-27040P4LOWCVSS 3.3≥ 2019, < 2019.1.3≥ 2020, < 2020.1.4+2 more2021-06-25
CVE-2021-27040 [LOW] CWE-125 CVE-2021-27040: A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DW
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
nvd
CVE-2005-4710P4MEDIUMCVSS 4.6v2005v20062005-12-31
CVE-2005-4710 [MEDIUM] CVE-2005-4710: Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 a
Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329.
nvd
CVE-2014-0819P4MEDIUMCVSS 4.4≤ 20132014-02-22
CVE-2014-0819 [MEDIUM] CWE-20 CVE-2014-0819: Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privi
Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
← Previous9 / 9