First published: Fri Aug 23 2019(Updated: )
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD Advance Steel | =2017 | |
Autodesk AutoCAD Advance Steel | =2018 | |
Autodesk AutoCAD Advance Steel | =2019 | |
Autodesk AutoCAD Advance Steel | =2020 | |
Autodesk AutoCAD 2024 | =2017 | |
Autodesk AutoCAD 2024 | =2018 | |
Autodesk AutoCAD 2024 | =2019 | |
Autodesk AutoCAD 2024 | =2020 | |
AutoCAD | =2017 | |
AutoCAD | =2018 | |
AutoCAD | =2019 | |
AutoCAD | =2020 | |
AutoCAD | =2017 | |
AutoCAD | =2018 | |
AutoCAD | =2019 | |
AutoCAD | =2020 | |
Autodesk AutoCAD LT 2017 | =2017 | |
Autodesk AutoCAD LT 2017 | =2018 | |
Autodesk AutoCAD LT 2017 | =2019 | |
Autodesk AutoCAD LT 2017 | =2020 | |
AutoCAD | =2017 | |
AutoCAD | =2018 | |
AutoCAD | =2019 | |
AutoCAD | =2020 | |
AutoCAD | =2017 | |
AutoCAD | =2018 | |
AutoCAD | =2019 | |
AutoCAD | =2020 | |
AutoCAD | =2017 | |
AutoCAD | =2018 | |
AutoCAD | =2019 | |
AutoCAD | =2020 | |
Autodesk AutoCAD P&ID | =2017 | |
AutoCAD | =2017 | |
AutoCAD | =2018 | |
AutoCAD | =2019 | |
AutoCAD | =2020 | |
Autodesk AutoCAD Civil 3D | =2017 | |
Autodesk AutoCAD Civil 3D | =2018 | |
Autodesk AutoCAD Civil 3D | =2019 | |
Autodesk AutoCAD Civil 3D | =2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2019-7364.
Versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, and version 2017 of AutoCAD P&ID are affected.
This vulnerability has a severity value of 7.8, which is classified as high.
An attacker can exploit this vulnerability by tricking a user into loading a malicious DLL file, which could lead to arbitrary code execution.
Yes, Autodesk has released a security advisory with instructions on how to mitigate this vulnerability. Please refer to the following link: [Autodesk Security Advisory](https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002)