Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25792


A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.


Published

2022-04-11T20:15:20.590

Last Modified

2024-11-21T06:53:00.663

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application autodesk advance_steel < 2019.1.4 Yes
Application autodesk advance_steel < 2020.1.5 Yes
Application autodesk advance_steel < 2021.1.2 Yes
Application autodesk advance_steel < 2022.1.2 Yes
Application autodesk autocad < 2019.1.4 Yes
Application autodesk autocad < 2020.1.5 Yes
Application autodesk autocad < 2021.1.2 Yes
Application autodesk autocad < 2022.1.2 Yes
Application autodesk autocad < 2022.2.2 Yes
Application autodesk autocad_architecture < 2019.1.4 Yes
Application autodesk autocad_architecture < 2020.1.5 Yes
Application autodesk autocad_architecture < 2021.1.2 Yes
Application autodesk autocad_architecture < 2022.1.2 Yes
Application autodesk autocad_electrical < 2019.1.4 Yes
Application autodesk autocad_electrical < 2020.1.5 Yes
Application autodesk autocad_electrical < 2021.1.2 Yes
Application autodesk autocad_electrical < 2022.1.2 Yes
Application autodesk autocad_lt < 2019.1.4 Yes
Application autodesk autocad_lt < 2020.1.5 Yes
Application autodesk autocad_lt < 2021.1.2 Yes
Application autodesk autocad_lt < 2022.1.2 Yes
Application autodesk autocad_map_3d < 2019.1.4 Yes
Application autodesk autocad_map_3d < 2020.1.5 Yes
Application autodesk autocad_map_3d < 2021.1.2 Yes
Application autodesk autocad_map_3d < 2022.1.2 Yes
Application autodesk autocad_mechanical < 2019.1.4 Yes
Application autodesk autocad_mechanical < 2020.1.5 Yes
Application autodesk autocad_mechanical < 2021.1.2 Yes
Application autodesk autocad_mechanical < 2022.1.2 Yes
Application autodesk autocad_mep < 2019.1.4 Yes
Application autodesk autocad_mep < 2020.1.5 Yes
Application autodesk autocad_mep < 2021.1.2 Yes
Application autodesk autocad_mep < 2022.1.2 Yes
Application autodesk autocad_plant_3d < 2019.1.4 Yes
Application autodesk autocad_plant_3d < 2020.1.5 Yes
Application autodesk autocad_plant_3d < 2021.1.2 Yes
Application autodesk autocad_plant_3d < 2022.1.2 Yes
Application autodesk civil_3d < 2019.1.4 Yes
Application autodesk civil_3d < 2020.1.5 Yes
Application autodesk civil_3d < 2021.1.2 Yes
Application autodesk civil_3d < 2022.1.2 Yes
Application autodesk navisworks < 2022.2 Yes

References