Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-33885


A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.


Published

2022-10-03T15:15:16.787

Last Modified

2024-11-21T07:08:31.707

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application autodesk autocad < 2022.1.3 Yes
Application autodesk autocad < 2023.1.1 Yes
Application autodesk autocad_advance_steel < 2022.1.3 Yes
Application autodesk autocad_advance_steel < 2023.1.1 Yes
Application autodesk autocad_architecture < 2022.1.3 Yes
Application autodesk autocad_architecture < 2023.1.1 Yes
Application autodesk autocad_civil_3d < 2022.1.3 Yes
Application autodesk autocad_civil_3d < 2023.1.1 Yes
Application autodesk autocad_electrical < 2022.1.3 Yes
Application autodesk autocad_electrical < 2023.1.1 Yes
Application autodesk autocad_lt < 2022.1.3 Yes
Application autodesk autocad_lt < 2023.1.1 Yes
Application autodesk autocad_map_3d < 2022.1.3 Yes
Application autodesk autocad_map_3d < 2023.1.1 Yes
Application autodesk autocad_mechanical < 2022.1.3 Yes
Application autodesk autocad_mechanical < 2023.1.1 Yes
Application autodesk autocad_mep < 2022.1.3 Yes
Application autodesk autocad_mep < 2023.1.1 Yes
Application autodesk autocad_plant_3d < 2022.1.3 Yes
Application autodesk autocad_plant_3d < 2023.1.1 Yes

References