Memory Corruption Vulnerability in Autodesk TrueView Products
CVE-2022-25795
7.8HIGH
Key Information:
Summary
A memory corruption vulnerability in Autodesk TrueView 2022 and 2021 can be exploited by attackers using specially crafted DWG files. This flaw may lead to remote code execution, putting users' systems at risk. It is essential for users to apply the recommended security updates from Autodesk to mitigate the risk of this vulnerability.
Affected Version(s)
Revit, Navisworks, Autodesk® Advance Steel, AutoCAD®, AutoCAD® Architecture, AutoCAD® Electrical, AutoCAD® Map 3D, AutoCAD® Mechanical, AutoCAD® MEP, AutoCAD® Plant 3D, AutoCAD® LT, Autodesk® Civil 3D, AutoCAD® Mac, AutoCAD® LT for Mac prior to 9.0.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved