Buffer overflow in Autodesk products - CVE-2022-41306
Published: December 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing PCT files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Advance Steel
Autodesk Civil 3D
AutoCAD LT
AutoCAD Plant 3D
AutoCAD MEP
AutoCAD Mechanical
AutoCAD Map 3D
AutoCAD Electrical
AutoCAD Architecture
Infrastructure Parts Editor
AutoCAD for Mac LT
AutoCAD Mac
Revit
DWG Trueview
Storm and Sanitary Analysis (SSA)
Autodesk AutoCAD
Autodesk Inventor
How to mitigate CVE-2022-41306
Advance Steel - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
Autodesk Civil 3D - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD LT - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD Plant 3D - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD MEP - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD Mechanical - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD Map 3D - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD Electrical - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
AutoCAD Architecture - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
Autodesk AutoCAD - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
Infrastructure Parts Editor - addressed in versions 2020.0.4, 2021.0.3, 2022.0.3, 2023.0.1
AutoCAD for Mac LT - addressed in versions 2021.3, 2022.3, 2023.2
AutoCAD Mac - addressed in versions 2021.3, 2022.3, 2023.2
Autodesk Inventor - addressed in versions 2022.4, 2023.2
Revit - update to 2023.1
DWG Trueview - addressed in versions 2020.1.6, 2021.1.3, 2022.1.3, 2023.1.1
Storm and Sanitary Analysis (SSA) - addressed in versions 2020.3.3, 2021.3.3, 2022.0.3, 2023.0.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Autodesk Design Review and AutoCAD programs
- Multiple vulnerabilities in AutoCAD for Mac
- Multiple vulnerabilities in Autodesk Revit
- Multiple vulnerabilities in Autodesk Inventor
- Multiple vulnerabilities in Autodesk Infrastructure Parts Editor
- Multiple vulnerabilities in Autodesk Storm and Sanitary Analysis
- Multiple vulnerabilities in Autodesk DWG Trueview