Memory Corruption Vulnerability in Autodesk TrueView Products
CVE-2022-25795

7.8HIGH

Summary

A memory corruption vulnerability in Autodesk TrueView 2022 and 2021 can be exploited by attackers using specially crafted DWG files. This flaw may lead to remote code execution, putting users' systems at risk. It is essential for users to apply the recommended security updates from Autodesk to mitigate the risk of this vulnerability.

Affected Version(s)

Revit, Navisworks, Autodesk® Advance Steel, AutoCAD®, AutoCAD® Architecture, AutoCAD® Electrical, AutoCAD® Map 3D, AutoCAD® Mechanical, AutoCAD® MEP, AutoCAD® Plant 3D, AutoCAD® LT, Autodesk® Civil 3D, AutoCAD® Mac, AutoCAD® LT for Mac prior to 9.0.7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.