First published: Fri Jun 25 2021(Updated: )
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Advance Steel | >=2019<2019.1.3 | |
Autodesk Advance Steel | >=2020<2020.1.4 | |
Autodesk Advance Steel | >=2021<2021.1.1 | |
Autodesk Advance Steel | >=2022<2022.0.1 | |
Autodesk Autocad | >=2019<2019.1.3 | |
Autodesk Autocad | >=2020<2020.1.4 | |
Autodesk Autocad | >=2021<2021.1.1 | |
Autodesk Autocad | >=2022<2022.0.1 | |
Autodesk AutoCAD Architecture | >=2019<2019.1.3 | |
Autodesk AutoCAD Architecture | >=2020<2020.1.4 | |
Autodesk AutoCAD Architecture | >=2021<2021.1.1 | |
Autodesk AutoCAD Architecture | >=2022<=2022.0.1 | |
Autodesk AutoCAD Electrical | >=2019<2019.1.3 | |
Autodesk AutoCAD Electrical | >=2020<2020.1.4 | |
Autodesk AutoCAD Electrical | >=2021<2021.1.1 | |
Autodesk AutoCAD Electrical | >=2022<2022.0.1 | |
Autodesk Autocad Lt | >=2019<2019.1.3 | |
Autodesk Autocad Lt | >=2020<2020.1.4 | |
Autodesk Autocad Lt | >=2021<2021.1.1 | |
Autodesk Autocad Lt | >=2022<2022.0.1 | |
Autodesk AutoCAD Map 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Map 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Map 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Map 3D | >=2022<2022.0.1 | |
Autodesk AutoCAD Mechanical | >=2019<2019.1.3 | |
Autodesk AutoCAD Mechanical | >=2020<2020.1.4 | |
Autodesk AutoCAD Mechanical | >=2021<2021.1.1 | |
Autodesk AutoCAD Mechanical | >=2022<2022.0.1 | |
Autodesk AutoCAD MEP | >=2019<2019.1.3 | |
Autodesk AutoCAD MEP | >=2020<2020.1.4 | |
Autodesk AutoCAD MEP | >=2021<2021.1.1 | |
Autodesk AutoCAD MEP | >=2022<2022.0.1 | |
Autodesk AutoCAD Plant 3D | >=2019<2019.1.3 | |
Autodesk AutoCAD Plant 3D | >=2020<2020.1.4 | |
Autodesk AutoCAD Plant 3D | >=2021<2021.1.1 | |
Autodesk AutoCAD Plant 3D | >=2022<2022.0.1 | |
Autodesk Civil 3D | >=2019<2019.1.3 | |
Autodesk Civil 3D | >=2020<2020.1.4 | |
Autodesk Civil 3D | >=2021<2021.1.1 | |
Autodesk Civil 3D | >=2022<2022.0.1 | |
Autodesk Dwg Trueview | >=2022<2022.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27043 is an Arbitrary Address Write issue in the Autodesk DWG application.
CVE-2021-27043 can allow a malicious user to leverage the application to write in unexpected paths.
CVE-2021-27043 has a severity rating of 7.8 (high).
Autodesk Advance Steel versions 2019-2022, Autodesk Autocad versions 2019-2022, Autodesk AutoCAD Architecture versions 2019-2022, Autodesk AutoCAD Electrical versions 2019-2022, Autodesk Autocad Lt versions 2019-2022, Autodesk AutoCAD Map 3D versions 2019-2022, Autodesk AutoCAD Mechanical versions 2019-2022, Autodesk AutoCAD MEP versions 2019-2022, Autodesk AutoCAD Plant 3D versions 2019-2022, Autodesk Civil 3D versions 2019-2022, and Autodesk Dwg Trueview version 2022.
To mitigate CVE-2021-27043, victim users should disable full page heap in the Autodesk DWG application.