Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-7361


An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018.


Published

2019-04-09T20:30:21.383

Last Modified

2024-11-21T04:48:05.923

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application autodesk advance_steel 2018 Yes
Application autodesk autocad 2018 Yes
Application autodesk autocad_architecture 2018 Yes
Application autodesk autocad_electrical 2018 Yes
Application autodesk autocad_lt 2018 Yes
Application autodesk autocad_map_3d 2018 Yes
Application autodesk autocad_mechanical 2018 Yes
Application autodesk autocad_mep 2018 Yes
Application autodesk autocad_p\&id 2018 Yes
Application autodesk autocad_plant_3d 2018 Yes
Application autodesk civil_3d 2018 Yes

References