First published: Fri Jun 25 2021(Updated: )
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
ICONICS GENESIS64 | ||
MC Works64 | ||
GENESIS64 AlarmWorX Multimedia | ||
AutoCAD | ||
Autodesk AutoCAD Advance Steel | >=2019<2019.1.3 | |
Autodesk AutoCAD Advance Steel | >=2020<2020.1.4 | |
Autodesk AutoCAD Advance Steel | >=2021<2021.1.1 | |
Autodesk AutoCAD Advance Steel | >=2022<2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<=2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<2022.0.1 | |
AutoCAD LT | >=2019<2019.1.3 | |
AutoCAD LT | >=2020<2020.1.4 | |
AutoCAD LT | >=2021<2021.1.1 | |
AutoCAD LT | >=2022<2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<2022.0.1 | |
AutoCAD | >=2019<2019.1.3 | |
AutoCAD | >=2020<2020.1.4 | |
AutoCAD | >=2021<2021.1.1 | |
AutoCAD | >=2022<2022.0.1 | |
Autodesk AutoCAD Civil 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Civil 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Civil 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Civil 3D | >=2022<2022.0.1 | |
Autodesk DWG TrueView 2023 | >=2022<2022.1.1 | |
GENESIS64 AlarmWorX Multimedia | <=10.97 | |
Mitsubishi Electric MC Works | <=4.04e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-27040.
The title of this vulnerability is ICONICS GENESIS64 DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability.
The affected software includes ICONICS GENESIS64, Autodesk Autocad, and Autodesk Advance Steel.
The severity of this vulnerability is high with a CVSS score of 7.8.
Yes, user interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.