Memory Corruption Vulnerability in Autodesk Image Processing Component
CVE-2021-40163

7.8HIGH

What is CVE-2021-40163?

A memory corruption vulnerability exists within the Autodesk Image Processing component, which could allow an attacker to execute arbitrary code by providing specially crafted DLL files. This exploitation potential emphasizes the importance of keeping software updated and ensuring that only trusted files are used within the Autodesk environment. For more details and mitigation strategies, visit the Autodesk security advisory.

Affected Version(s)

Revit, Inventor, Infraworks, Navisworks, Fusion, Infrastructure Parts Editors, Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D 2022, 2021, 2020, 2019

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.