CVE-2019-7364: High severity autodesk autocad advance steel vulnerability
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2019-7364.
Which software versions are affected by this vulnerability?
Versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, and version 2017 of AutoCAD P&ID are affected.
How severe is this vulnerability?
This vulnerability has a severity value of 7.8, which is classified as high.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by tricking a user into loading a malicious DLL file, which could lead to arbitrary code execution.
Is there a fix for this vulnerability?
Yes, Autodesk has released a security advisory with instructions on how to mitigate this vulnerability. Please refer to the following link: [Autodesk Security Advisory](https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002)