Out-of-Bounds Read in Autodesk TrueView Leading to Information Exposure
CVE-2022-27524
7.1HIGH
Summary
An out-of-bounds read vulnerability exists in Autodesk TrueView 2022, which can be exploited by using a specially crafted DWG file. This could result in the exposure of sensitive information or cause the application to crash. Moreover, when combined with other vulnerabilities, this issue may potentially allow for code execution in the current process context, increasing the risk to user systems. It is essential for users to apply the necessary updates and practices to mitigate this potential threat.
Affected Version(s)
Autodesk Trueview 2022.1.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved