#VU67689 Uncaught exception in Autodesk products - CVE-2022-33887
Published: September 27, 2022 / Updated: September 30, 2022
Vulnerability identifier: #VU67689
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-33887
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Autodesk AutoCAD
AutoCAD Architecture
AutoCAD Electrical
AutoCAD Map 3D
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
AutoCAD LT
Autodesk Civil 3D
Advance Steel
Autodesk AutoCAD
AutoCAD Architecture
AutoCAD Electrical
AutoCAD Map 3D
AutoCAD Mechanical
AutoCAD MEP
AutoCAD Plant 3D
AutoCAD LT
Autodesk Civil 3D
Advance Steel
Software vendor:
Autodesk
Autodesk
Description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to an uncaught exception when handling PDF files. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and crash the application.
Remediation
Install updates from vendor's website.