Improper Input Validation in Autodesk Navisworks Affects Multiple Versions
CVE-2021-40155

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
15 September 2021

Summary

A vulnerability in Autodesk Navisworks across multiple versions allows an attacker to exploit a maliciously crafted DWG file. The flaw permits the application to read beyond its allocated memory boundaries while processing these files, potentially leading to arbitrary code execution. Users of Navisworks should remain vigilant and apply necessary patches to mitigate this risk.

Affected Version(s)

Autodesk Navisworks 2019, 2020, 2021, 2022

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.