CVE-2021-27033: Double Free File Parsing Vulnerability in Autodesk Design Review

Published Jul 9, 2021
·
Updated

A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Other sources

A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.

MITRE

Affected Software

5 affected components
Autodesk Design Review=2011
Autodesk Design Review=2012
Autodesk Design Review=2013
Autodesk Design Review=2017
Autodesk Design Review=2018

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Autodesk Design Review 2011 from your environment.

    Uninstall Autodesk Design Review 2011 from systems where it is not required to eliminate the vulnerable PDF-parsing component until a vendor-supplied fix is available.

  2. Compensating control

    Block or filter PDF files from untrusted sources at email gateways, web proxies, and perimeter appliances (NGFW/WAF) to prevent delivery of malicious PDFs to hosts running Autodesk Design Review.

  3. Compensating control

    Isolate or restrict network access for systems running Autodesk Design Review (segmentation, host-based firewall rules, or deny Internet access) to reduce exposure to remote attacks that rely on visiting malicious pages.

  4. Operational

    Instruct users not to open PDFs from untrusted sources or click unknown links. If a suspicious or malicious PDF was opened in Autodesk Design Review, perform incident response actions (scan the host for compromise, isolate the host, and rotate any potentially exposed credentials).

Event History

Jul 9, 2021
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-27033?

CVE-2021-27033 is a Double Free vulnerability that allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011.

2

How does CVE-2021-27033 work?

CVE-2021-27033 works by exploiting a Double Free vulnerability in the affected versions of Autodesk Design Review, which allows remote attackers to execute arbitrary code on PDF files.

3

What is the severity of CVE-2021-27033?

The severity of CVE-2021-27033 is high, with a CVSS score of 7.8.

4

How can CVE-2021-27033 be exploited?

CVE-2021-27033 can be exploited by tricking the target into visiting a malicious webpage or opening a malicious PDF file.

5

Is there a fix for CVE-2021-27033?

Yes, updating to the latest version of Autodesk Design Review will fix the CVE-2021-27033 vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203