CVE-2014-9268: Input Validation
Published Dec 8, 2014
·Updated
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
Affected Software
1 affected component
Autodesk Design Review<=2013
Remediation
Event History
Dec 8, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9268?
CVE-2014-9268 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-9268?
To fix CVE-2014-9268, upgrade Autodesk Design Review to version 2013 Hotfix 1 or later.
3
What types of attacks can exploit CVE-2014-9268?
CVE-2014-9268 can be exploited through crafted DWF files that trigger the vulnerability in the ActiveX control.
4
What software is affected by CVE-2014-9268?
CVE-2014-9268 affects Autodesk Design Review versions prior to 2013 Hotfix 1.
5
What are the implications of CVE-2014-9268?
Exploitation of CVE-2014-9268 could allow attackers to execute arbitrary code on the user's machine.