CVE-2021-40155: High severity Autodesk Navisworks vulnerability
A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40155?
CVE-2021-40155 is a vulnerability found in Autodesk Navisworks 2019, 2020, 2021, and 2022 that allows a maliciously crafted DWG file to read beyond allocated boundaries, potentially leading to arbitrary code execution.
How can CVE-2021-40155 be exploited?
CVE-2021-40155 can be exploited by using a specially crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, or 2022.
What is the severity of CVE-2021-40155?
CVE-2021-40155 has a severity score of 7.8 (high).
Which versions of Autodesk Navisworks are affected by CVE-2021-40155?
Autodesk Navisworks 2019, 2020, 2021, and 2022 are affected by CVE-2021-40155.
How can I fix CVE-2021-40155?
To fix CVE-2021-40155, it is recommended to apply the latest security patches and updates provided by Autodesk.