A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
2022-10-03T15:15:16.787
2024-11-21T07:08:31.707
Modified
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | autodesk | autocad | < 2022.1.3 | Yes |
| Application | autodesk | autocad | < 2023.1.1 | Yes |
| Application | autodesk | autocad_advance_steel | < 2022.1.3 | Yes |
| Application | autodesk | autocad_advance_steel | < 2023.1.1 | Yes |
| Application | autodesk | autocad_architecture | < 2022.1.3 | Yes |
| Application | autodesk | autocad_architecture | < 2023.1.1 | Yes |
| Application | autodesk | autocad_civil_3d | < 2022.1.3 | Yes |
| Application | autodesk | autocad_civil_3d | < 2023.1.1 | Yes |
| Application | autodesk | autocad_electrical | < 2022.1.3 | Yes |
| Application | autodesk | autocad_electrical | < 2023.1.1 | Yes |
| Application | autodesk | autocad_lt | < 2022.1.3 | Yes |
| Application | autodesk | autocad_lt | < 2023.1.1 | Yes |
| Application | autodesk | autocad_map_3d | < 2022.1.3 | Yes |
| Application | autodesk | autocad_map_3d | < 2023.1.1 | Yes |
| Application | autodesk | autocad_mechanical | < 2022.1.3 | Yes |
| Application | autodesk | autocad_mechanical | < 2023.1.1 | Yes |
| Application | autodesk | autocad_mep | < 2022.1.3 | Yes |
| Application | autodesk | autocad_mep | < 2023.1.1 | Yes |
| Application | autodesk | autocad_plant_3d | < 2022.1.3 | Yes |
| Application | autodesk | autocad_plant_3d | < 2023.1.1 | Yes |