CVE-2021-27033: Double Free File Parsing Vulnerability in Autodesk Design Review
A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Other sources
A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Autodesk Design Review 2011from your environment.Uninstall Autodesk Design Review 2011 from systems where it is not required to eliminate the vulnerable PDF-parsing component until a vendor-supplied fix is available.
- Compensating control
Block or filter PDF files from untrusted sources at email gateways, web proxies, and perimeter appliances (NGFW/WAF) to prevent delivery of malicious PDFs to hosts running Autodesk Design Review.
- Compensating control
Isolate or restrict network access for systems running Autodesk Design Review (segmentation, host-based firewall rules, or deny Internet access) to reduce exposure to remote attacks that rely on visiting malicious pages.
- Operational
Instruct users not to open PDFs from untrusted sources or click unknown links. If a suspicious or malicious PDF was opened in Autodesk Design Review, perform incident response actions (scan the host for compromise, isolate the host, and rotate any potentially exposed credentials).
Event History
Frequently Asked Questions
What is CVE-2021-27033?
CVE-2021-27033 is a Double Free vulnerability that allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011.
How does CVE-2021-27033 work?
CVE-2021-27033 works by exploiting a Double Free vulnerability in the affected versions of Autodesk Design Review, which allows remote attackers to execute arbitrary code on PDF files.
What is the severity of CVE-2021-27033?
The severity of CVE-2021-27033 is high, with a CVSS score of 7.8.
How can CVE-2021-27033 be exploited?
CVE-2021-27033 can be exploited by tricking the target into visiting a malicious webpage or opening a malicious PDF file.
Is there a fix for CVE-2021-27033?
Yes, updating to the latest version of Autodesk Design Review will fix the CVE-2021-27033 vulnerability.