cbcvebase.

Autodesk Installer vulnerabilities

6 known vulnerabilities affecting autodesk/installer.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-14478P3HIGHCVSS 7.8fixed in 2.23≥ 2.22.0, < 2.23.02026-08-12
CVE-2026-14478 [HIGH] CWE-732 CVE-2026-14478: A maliciously created executable, when executed on the victim's machine, may allow a local low-privi A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.
nvd
CVE-2025-10885P3HIGHCVSS 7.8fixed in 2.19≥ 2.18, < 2.192025-11-06
CVE-2025-10885 [HIGH] CWE-250 CVE-2025-10885: A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.
nvd
CVE-2025-5335P3HIGHCVSS 7.8fixed in 2.15≥ 2.13, < 2.152025-06-10
CVE-2025-5335 [HIGH] CWE-426 CVE-2025-5335: A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHO A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.
nvd
CVE-2024-9500P3HIGHCVSS 7.8fixed in 2.10.0.20≥ 2.10.0.17, < 2.10.0.202024-11-15
CVE-2024-9500 [HIGH] CWE-379 CVE-2024-9500: A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.
nvd
CVE-2023-27908P3HIGHCVSS 7.8≥ 1.29.0.90, < 1.39.0.2162023-06-23
CVE-2023-27908 [HIGH] CWE-427 CVE-2023-27908: A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk in A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability.
nvd
CVE-2026-14479P4MEDIUMCVSS 5.5fixed in 2.23≥ 2.22.0, < 2.23.02026-08-12
CVE-2026-14479 [MEDIUM] CWE-1285 CVE-2026-14479: A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial
nvd
Autodesk Installer vulnerabilities | cvebase