Description
A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe application while parsing TGA and PCX files. This vulnerability may be exploited to execute arbitrary code.
Related CPE's
a
autodesk
design_review
10
References
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0009
PatchVendor Advisory
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0009
PatchVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-07-29T18:15:12.217Z
3 years agoLast modified
2024-11-21T05:56:21.473Z
1 year ago