Memory Corruption Flaw in Autodesk AutoCAD and Navisworks Products
CVE-2022-25791
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 11 April 2022
Summary
A memory corruption flaw has been identified in Autodesk AutoCAD and Navisworks products, affecting various versions. This vulnerability can be exploited through maliciously crafted DWF and DWFX files, potentially leading to unauthorized code execution via DLL files. Users are advised to apply recommended security measures to mitigate risks associated with this issue.
Affected Version(s)
Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D 2022.1.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved