First published: Wed Sep 15 2021(Updated: )
A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Navisworks | =2019 | |
Autodesk Navisworks | =2020 | |
Autodesk Navisworks | =2021 | |
Autodesk Navisworks | =2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40155 is a vulnerability found in Autodesk Navisworks 2019, 2020, 2021, and 2022 that allows a maliciously crafted DWG file to read beyond allocated boundaries, potentially leading to arbitrary code execution.
CVE-2021-40155 can be exploited by using a specially crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, or 2022.
CVE-2021-40155 has a severity score of 7.8 (high).
Autodesk Navisworks 2019, 2020, 2021, and 2022 are affected by CVE-2021-40155.
To fix CVE-2021-40155, it is recommended to apply the latest security patches and updates provided by Autodesk.