CVE-2022-27523

A buffer over-read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*

History

21 Apr 2022, 16:50

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.8
v3 : 7.1
CWE CWE-125
References (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007 - (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007 - Vendor Advisory
First Time Autodesk dwg Trueview
Autodesk

13 Apr 2022, 18:55

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-13 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-27523

Mitre link : CVE-2022-27523

CVE.ORG link : CVE-2022-27523


JSON object : View

Products Affected

autodesk

  • dwg_trueview
CWE
CWE-125

Out-of-bounds Read