Memory Corruption Vulnerability in Autodesk's Design Review Application
CVE-2022-42939

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
21 October 2022

Summary

A memory corruption vulnerability exists in Autodesk's Design Review application when processing specially crafted TGA files. Attackers exploiting this vulnerability could potentially execute arbitrary code under the permissions of the running process. This issue highlights the importance of secure file handling and the necessity for users to apply patches or updates provided by Autodesk to mitigate potential risks.

Affected Version(s)

Autodesk Design Review 2018, 2017, 2013, 2012, 2011

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.