First published: Thu Dec 23 2021(Updated: )
PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Revit | >=2020<2020.2.5 | |
Autodesk Revit | >=2021<2021.1.4 | |
Autodesk Revit | >=2022<2022.1 | |
Autodesk Navisworks | >=2019<2019.6 | |
Autodesk Navisworks | >=2020<2020.4 | |
Autodesk Navisworks | >=2021<2021.3 | |
Autodesk Navisworks | >=2022<2022.1 | |
Autodesk Advance Steel | >=2022<2022.1.1 | |
Autodesk Autocad | >=2022<2022.1.1 | |
Autodesk Autocad | >=2022<2022.2 | |
Autodesk AutoCAD Architecture | >=2022<2022.1.1 | |
Autodesk AutoCAD Electrical | >=2022<2022.1.1 | |
Autodesk Autocad Lt | >=2022<2022.1.1 | |
Autodesk Autocad Lt | >=2022<2022.2 | |
Autodesk AutoCAD Map 3D | >=2022<2022.1.1 | |
Autodesk AutoCAD Mechanical | >=2022<2022.1.1 | |
Autodesk AutoCAD MEP | >=2022<2022.1.1 | |
Autodesk AutoCAD Plant 3D | >=2022<2022.1.1 | |
Autodesk Civil 3D | >=2022<2022.1.1 | |
Autodesk Design Review | =2018 | |
Autodesk Design Review | =2018-hotfix | |
Autodesk Design Review | =2018-hotfix2 | |
Autodesk Design Review | =2018-hotfix3 | |
Autodesk Design Review | =2018-hotfix4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40160 is a vulnerability in PDFTron prior to version 9.0.7 that allows for the execution of arbitrary code by forcing the application to read beyond allocated boundaries when parsing a malicious PDF file.
CVE-2021-40160 affects Autodesk Revit versions 2020 and 2021, Autodesk Navisworks versions 2019, 2020, and 2021, Autodesk Advance Steel version 2022, and Autodesk AutoCAD versions 2022 and 2022.2, among others.
CVE-2021-40160 has a severity score of 7.8 (high severity).
To fix CVE-2021-40160, you should update PDFTron to version 9.0.7 or later. Make sure to download the latest version from the official PDFTron website.
You can find more information about CVE-2021-40160 in the Autodesk security advisory AD-SK-SA-2021-0010, available at the following link: https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010