DLL Search Order Hijacking Vulnerability in DWG TrueView by Autodesk
CVE-2022-42945

7.8HIGH

Key Information:

Vendor

Autodesk

Vendor
CVE Published:
19 December 2022

What is CVE-2022-42945?

DWG TrueView 2023 contains a DLL Search Order Hijacking vulnerability that could be exploited by malicious actors to execute unauthorized code on the affected system. If successfully executed, this vulnerability could lead to significant security risks for users, allowing attackers to manipulate system operations and access sensitive information.

Affected Version(s)

DWG TrueView 2023

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.