First published: Fri Jun 25 2021(Updated: )
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Advance Steel | >=2019<2019.1.3 | |
Autodesk Advance Steel | >=2020<2020.1.4 | |
Autodesk Advance Steel | >=2021<2021.1.1 | |
Autodesk Advance Steel | >=2022<2022.0.1 | |
Autodesk Autocad | >=2019<2019.1.3 | |
Autodesk Autocad | >=2020<2020.1.4 | |
Autodesk Autocad | >=2021<2021.1.1 | |
Autodesk Autocad | >=2022<2022.0.1 | |
Autodesk AutoCAD Architecture | >=2019<2019.1.3 | |
Autodesk AutoCAD Architecture | >=2020<2020.1.4 | |
Autodesk AutoCAD Architecture | >=2021<2021.1.1 | |
Autodesk AutoCAD Architecture | >=2022<=2022.0.1 | |
Autodesk AutoCAD Electrical | >=2019<2019.1.3 | |
Autodesk AutoCAD Electrical | >=2020<2020.1.4 | |
Autodesk AutoCAD Electrical | >=2021<2021.1.1 | |
Autodesk AutoCAD Electrical | >=2022<2022.0.1 | |
Autodesk Autocad Lt | >=2019<2019.1.3 | |
Autodesk Autocad Lt | >=2020<2020.1.4 | |
Autodesk Autocad Lt | >=2021<2021.1.1 | |
Autodesk Autocad Lt | >=2022<2022.0.1 | |
Autodesk AutoCAD Map 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Map 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Map 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Map 3D | >=2022<2022.0.1 | |
Autodesk AutoCAD Mechanical | >=2019<2019.1.3 | |
Autodesk AutoCAD Mechanical | >=2020<2020.1.4 | |
Autodesk AutoCAD Mechanical | >=2021<2021.1.1 | |
Autodesk AutoCAD Mechanical | >=2022<2022.0.1 | |
Autodesk AutoCAD MEP | >=2019<2019.1.3 | |
Autodesk AutoCAD MEP | >=2020<2020.1.4 | |
Autodesk AutoCAD MEP | >=2021<2021.1.1 | |
Autodesk AutoCAD MEP | >=2022<2022.0.1 | |
Autodesk AutoCAD Plant 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Plant 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Plant 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Plant 3D | >=2022<2022.0.1 | |
Autodesk Civil 3D | >=2019<2019.1.3 | |
Autodesk Civil 3D | >=2020<2020.1.4 | |
Autodesk Civil 3D | >=2021<2021.1.1 | |
Autodesk Civil 3D | >=2022<2022.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-27042.
The severity of CVE-2021-27042 is high with a CVSS score of 7.8.
The software products affected by CVE-2021-27042 include Autodesk Advance Steel (versions 2019 - 2022), Autodesk Autocad (versions 2019 - 2022), Autodesk AutoCAD Architecture (versions 2019 - 2022), Autodesk AutoCAD Electrical (versions 2019 - 2022), Autodesk Autocad Lt (versions 2019 - 2022), Autodesk AutoCAD Map 3D (versions 2019 - 2022), Autodesk AutoCAD Mechanical (versions 2019 - 2022), Autodesk AutoCAD MEP (versions 2019 - 2022), Autodesk AutoCAD Plant 3D (versions 2019 - 2022), and Autodesk Civil 3D (versions 2019 - 2022).
The vulnerability in CVE-2021-27042 allows a maliciously crafted DWG file to write beyond the allocated buffer while parsing DWG files, leading to an unhandled exception and potential execution of arbitrary code.
Yes, Autodesk has released a security advisory with a fix for CVE-2021-27042. To protect against this vulnerability, users should update their affected software to the latest available version.