#VU61950 Out-of-bounds read in Autodesk products - CVE-2022-27523

 

#VU61950 Out-of-bounds read in Autodesk products - CVE-2022-27523

Published: April 7, 2022


Vulnerability identifier: #VU61950
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-27523
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
DWG Trueview
Autodesk Civil 3D
AutoCAD Map 3D
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
AutoCAD LT
Advance Steel
AutoCAD for Mac
AutoCAD for Mac LT
AutoCAD Electrical
AutoCAD Architecture
Autodesk AutoCAD
Software vendor:
Autodesk

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote user can create a specially crafted DWG file file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.


Remediation

Install updates from vendor's website.

External links