Memory Corruption Vulnerability in Autodesk Software
CVE-2022-41307

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
14 October 2022

Summary

A vulnerability exists within Autodesk's SubassemblyComposer application that can be triggered by processing a specially crafted PKT file. This flaw may result in memory corruption through a read access violation, potentially allowing malicious actors to execute arbitrary code in the context of the current process. Addressing this vulnerability is crucial, especially when combined with other existing security flaws.

Affected Version(s)

Subassembly Composer 2023, 2022, 2021, 2021

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.