Description


Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.

Related CPE's


a

autodesk

3ds_max

2

a

autodesk

advance_steel

4

a

autodesk

autocad

5

a

autodesk

autocad_architecture

4

a

autodesk

autocad_civil_3d

4

a

autodesk

autocad_electrical

4

a

autodesk

autocad_lt

5

a

autodesk

autocad_map_3d

4

a

autodesk

autocad_mechanical

4

a

autodesk

autocad_mep

4

a

autodesk

autocad_plant_3d

4


a

autodesk

navisworks

3

a

autodesk

revit

3

Weaknesses



CWE-770

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-06-21T15:15:08.863

3 years ago

Last modified

2022-06-29T17:18:31.377

3 years ago