Buffer Overflow Vulnerability in Autodesk AutoCAD Product Suite
CVE-2022-27871

7.8HIGH

Key Information:

Summary

A vulnerability in the Autodesk AutoCAD product suite, including Revit, Design Review, and Navisworks, allows for a buffer overflow due to improper parsing of PDF files using PDFTron prior to version 9.1.17. This flaw could enable an attacker to write beyond the allocated buffer, posing a risk of arbitrary code execution within the affected applications.

Affected Version(s)

Autodesk AutoCAD product suite, Revit, Design Review and Navisworks 2022, 2021, 2020,2019

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.