A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
Link | Resource |
---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0021 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Oct 2022, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. |
05 Oct 2022, 14:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Autodesk
Autodesk autocad Architecture Autodesk autocad Civil 3d Autodesk autocad Map 3d Autodesk autocad Advance Steel Autodesk autocad Autodesk autocad Lt Autodesk autocad Electrical Autodesk design Review Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0021 - Vendor Advisory | |
CWE | CWE-787 | |
CPE | cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:hotfix6:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:hotfix5:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:* |
03 Oct 2022, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-10-03 15:15
Updated : 2023-12-10 14:35
NVD link : CVE-2022-33890
Mitre link : CVE-2022-33890
CVE.ORG link : CVE-2022-33890
JSON object : View
Products Affected
autodesk
- autocad_plant_3d
- autocad_electrical
- autocad_lt
- autocad_mep
- autocad_civil_3d
- autocad
- autocad_advance_steel
- autocad_mechanical
- autocad_map_3d
- autocad_architecture
- design_review
CWE
CWE-787
Out-of-bounds Write