#VU54376 Out-of-bounds read in Autodesk AutoCAD - CVE-2021-27040
Published: June 24, 2021 / Updated: March 8, 2022
Autodesk AutoCAD
Autodesk
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing DWG and PDF files. A remote attacker can create a specially crafted DWG file, trick the victim into opening it, trigger an out-of-bounds read and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004
- https://fortiguard.com/zeroday/FG-VD-20-137
- https://www.zerodayinitiative.com/advisories/ZDI-21-712/
- https://www.zerodayinitiative.com/advisories/ZDI-21-711/
- https://www.zerodayinitiative.com/advisories/ZDI-21-710/
- https://www.zerodayinitiative.com/advisories/ZDI-21-709/
- https://www.zerodayinitiative.com/advisories/ZDI-21-708/
- https://www.zerodayinitiative.com/advisories/ZDI-21-707/
- https://www.zerodayinitiative.com/advisories/ZDI-21-706/
- https://www.zerodayinitiative.com/advisories/ZDI-21-1238/
- https://www.zerodayinitiative.com/advisories/ZDI-21-1236/
- https://www.zerodayinitiative.com/advisories/ZDI-22-473/