First published: Fri Jun 25 2021(Updated: )
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Advance Steel | >=2019<2019.1.3 | |
Autodesk Advance Steel | >=2020<2020.1.4 | |
Autodesk Advance Steel | >=2021<2021.1.1 | |
Autodesk Advance Steel | >=2022<2022.0.1 | |
Autodesk Autocad | >=2019<2019.1.3 | |
Autodesk Autocad | >=2020<2020.1.4 | |
Autodesk Autocad | >=2021<2021.1.1 | |
Autodesk Autocad | >=2022<2022.0.1 | |
Autodesk AutoCAD Architecture | >=2019<2019.1.3 | |
Autodesk AutoCAD Architecture | >=2020<2020.1.4 | |
Autodesk AutoCAD Architecture | >=2021<2021.1.1 | |
Autodesk AutoCAD Architecture | >=2022<=2022.0.1 | |
Autodesk AutoCAD Electrical | >=2019<2019.1.3 | |
Autodesk AutoCAD Electrical | >=2020<2020.1.4 | |
Autodesk AutoCAD Electrical | >=2021<2021.1.1 | |
Autodesk AutoCAD Electrical | >=2022<2022.0.1 | |
Autodesk Autocad Lt | >=2019<2019.1.3 | |
Autodesk Autocad Lt | >=2020<2020.1.4 | |
Autodesk Autocad Lt | >=2021<2021.1.1 | |
Autodesk Autocad Lt | >=2022<2022.0.1 | |
Autodesk AutoCAD Map 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Map 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Map 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Map 3D | >=2022<2022.0.1 | |
Autodesk AutoCAD Mechanical | >=2019<2019.1.3 | |
Autodesk AutoCAD Mechanical | >=2020<2020.1.4 | |
Autodesk AutoCAD Mechanical | >=2021<2021.1.1 | |
Autodesk AutoCAD Mechanical | >=2022<2022.0.1 | |
Autodesk AutoCAD MEP | >=2019<2019.1.3 | |
Autodesk AutoCAD MEP | >=2020<2020.1.4 | |
Autodesk AutoCAD MEP | >=2021<2021.1.1 | |
Autodesk AutoCAD MEP | >=2022<2022.0.1 | |
Autodesk AutoCAD Plant 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Plant 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Plant 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Plant 3D | >=2022<2022.0.1 | |
Autodesk Civil 3D | >=2019<2019.1.3 | |
Autodesk Civil 3D | >=2020<2020.1.4 | |
Autodesk Civil 3D | >=2021<2021.1.1 | |
Autodesk Civil 3D | >=2022<2022.0.1 | |
Autodesk Dwg Trueview | >=2022<2022.1.1 | |
ICONICS GENESIS64 | <=10.97 | |
Mitsubishielectric Mc Works64 | <=4.04e | |
Autodesk Autocad | ||
ICONICS GENESIS64 | ||
ICONICS, Mitsubishi Electric GENESIS64 (all versions up to and including 10.97) | ||
ICONICS, Mitsubishi Electric MC Works64 (all version of MC Works64, up to and including Version 4.04E) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-27040.
The title of this vulnerability is ICONICS GENESIS64 DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability.
The affected software includes ICONICS GENESIS64, Autodesk Autocad, and Autodesk Advance Steel.
The severity of this vulnerability is high with a CVSS score of 7.8.
Yes, user interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.