Arbitrary Address Write Vulnerability in Autodesk DWG Application
CVE-2021-27043

7.8HIGH

Summary

The Autodesk DWG application contains an Arbitrary Address Write vulnerability that could allow an attacker to exploit the application to write data to unexpected and potentially harmful locations in the system. For this security risk to be successfully exploited, the attacker must persuade the user to enable the full page heap feature within the application. This exploit could lead to unauthorized modifications or access to sensitive data, undermining the integrity of the impacted systems.

Affected Version(s)

Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D 2022.1.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.