Memory Corruption Vulnerability in Autodesk Design Review
CVE-2021-40167

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
25 January 2022

Summary

The vulnerability allows specially crafted DWF or PCT files to be processed by the DesignReview.exe application, resulting in a memory corruption issue due to read access violations. This flaw may be exploited in conjunction with other vulnerabilities, potentially enabling arbitrary code execution within the context of the affected application. Organizations using Autodesk Design Review should assess their exposure to risk and apply necessary mitigations.

Affected Version(s)

AutodeskĀ® Design Review 2018

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.