CVE-2021-40161: High severity autodesk revit 2025 vulnerability
Published Dec 23, 2021
·Updated
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.
Affected Software
59 affected components
Autodesk Revit<2020.2.5
Autodesk Revit>=2021<2021.1.6
Autodesk Revit>=2022<2022.1.2
Autodesk Navisworks<2019.6
Autodesk Navisworks>=2020<2020.4
Autodesk Navisworks>=2021<2021.3
Autodesk Navisworks>=2022<2022.2
Autodesk Advance Steel<2019.1.4
Autodesk Advance Steel>=2020<2020.1.5
Autodesk Advance Steel>=2021<2021.1.2
Autodesk Advance Steel>=2022<2022.1.2
Autodesk AutoCAD<2019.1.4
Autodesk AutoCAD>=2020<2020.1.5
Autodesk AutoCAD>=2021<2021.1.2
Autodesk AutoCAD>=2022<2022.1.2
Autodesk AutoCAD Architecture<2019.1.4
Autodesk AutoCAD Architecture>=2020<2020.1.5
Autodesk AutoCAD Architecture>=2021<2021.1.2
Autodesk AutoCAD Architecture>=2022<2022.1.2
Autodesk AutoCAD Electrical<2019.1.4
Autodesk AutoCAD Electrical>=2020<2020.1.5
Autodesk AutoCAD Electrical>=2021<2021.1.2
Autodesk AutoCAD Electrical>=2022<2022.1.2
Autodesk AutoCAD Map 3D<2019.1.4
Autodesk AutoCAD Map 3D>=2020<2020.1.5
Autodesk AutoCAD Map 3D>=2021<2021.1.2
Autodesk AutoCAD Map 3D>=2022<2022.1.2
Autodesk AutoCAD Mechanical<2019.1.4
Autodesk AutoCAD Mechanical>=2020<2020.1.5
Autodesk AutoCAD Mechanical>=2021<2021.1.2
Autodesk AutoCAD Mechanical>=2022<2022.1.2
Autodesk AutoCAD MEP<2019.1.4
Autodesk AutoCAD MEP>=2020<2020.1.5
Autodesk AutoCAD MEP>=2021<2021.1.2
Autodesk AutoCAD MEP>=2022<2022.1.2
Autodesk AutoCAD Plant 3D<2019.1.4
Autodesk AutoCAD Plant 3D>=2020<2020.1.5
Autodesk AutoCAD Plant 3D>=2021<2021.1.2
Autodesk AutoCAD Plant 3D>=2022<2022.1.2
Autodesk AutoCAD LT<2019.1.4
Autodesk AutoCAD LT>=2020<2020.1.5
Autodesk AutoCAD LT>=2021<2021.1.2
Autodesk AutoCAD LT>=2022<2022.1.2
Autodesk Civil 3D<2019.1.4
Autodesk Civil 3D>=2020<2020.1.5
Autodesk Civil 3D>=2021<2021.1.2
Autodesk Civil 3D>=2022<2022.1.2
Autodesk Autocad Macos>2022<2022.2
Autodesk Autocad Macos=2020
Autodesk Autocad Macos=2021
Autodesk Autocad Macos=2022
Autodesk Autocad Lt Macos>=2022<2022.2
Autodesk Autocad Lt Macos=2020
Autodesk Autocad Lt Macos=2021
Autodesk Design Review=2018
Autodesk Design Review=2018-hotfix
Autodesk Design Review=2018-hotfix2
Autodesk Design Review=2018-hotfix3
Autodesk Design Review=2018-hotfix4
Remediation
Event History
Dec 23, 2021
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-40161?
CVE-2021-40161 is considered a critical vulnerability due to the potential for code execution through maliciously crafted DLL files.
2
How do I fix CVE-2021-40161?
To fix CVE-2021-40161, update your affected Autodesk software to version 9.0.7 or later.
3
What products are affected by CVE-2021-40161?
CVE-2021-40161 affects several versions of Autodesk products including Revit, Navisworks, AutoCAD, and others prior to specific versions.
4
What type of attack does CVE-2021-40161 enable?
CVE-2021-40161 enables a memory corruption attack that can lead to remote code execution.
5
Is there a workaround for CVE-2021-40161?
There are no confirmed workarounds for CVE-2021-40161; the best course of action is to apply the necessary updates.