Out-of-bounds read in Autodesk products - CVE-2022-27523

 

Out-of-bounds read in Autodesk products - CVE-2022-27523

Published: April 7, 2022


Vulnerability identifier: #VU61950
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-27523
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Autodesk
Affected software:
DWG Trueview
Autodesk Civil 3D
AutoCAD Map 3D
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
AutoCAD LT
Advance Steel
AutoCAD for Mac
AutoCAD for Mac LT
AutoCAD Electrical
AutoCAD Architecture
Autodesk AutoCAD

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote user can create a specially crafted DWG file file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.


How to mitigate CVE-2022-27523

Install updates from vendor's website.

Sources