Buffer Overflow Vulnerability in Autodesk AutoCAD Product Suite
CVE-2022-27871
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 21 June 2022
Summary
A vulnerability in the Autodesk AutoCAD product suite, including Revit, Design Review, and Navisworks, allows for a buffer overflow due to improper parsing of PDF files using PDFTron prior to version 9.1.17. This flaw could enable an attacker to write beyond the allocated buffer, posing a risk of arbitrary code execution within the affected applications.
Affected Version(s)
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks 2022, 2021, 2020,2019
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved