First published: Thu Dec 23 2021(Updated: )
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Revit 2025 | <2020.2.5 | |
Autodesk Revit 2025 | >=2021<2021.1.6 | |
Autodesk Revit 2025 | >=2022<2022.1.2 | |
Autodesk Navisworks | <2019.6 | |
Autodesk Navisworks | >=2020<2020.4 | |
Autodesk Navisworks | >=2021<2021.3 | |
Autodesk Navisworks | >=2022<2022.2 | |
Autodesk AutoCAD Advance Steel | <2019.1.4 | |
Autodesk AutoCAD Advance Steel | >=2020<2020.1.5 | |
Autodesk AutoCAD Advance Steel | >=2021<2021.1.2 | |
Autodesk AutoCAD Advance Steel | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | <2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD LT | <2019.1.4 | |
AutoCAD LT | >=2020<2020.1.5 | |
AutoCAD LT | >=2021<2021.1.2 | |
AutoCAD LT | >=2022<2022.1.2 | |
Autodesk AutoCAD Civil 3D | <2019.1.4 | |
Autodesk AutoCAD Civil 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Civil 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Civil 3D | >=2022<2022.1.2 | |
Autodesk AutoCAD LT for macOS | >2022<2022.2 | |
Autodesk AutoCAD LT for macOS | =2020 | |
Autodesk AutoCAD LT for macOS | =2021 | |
Autodesk AutoCAD LT for macOS | =2022 | |
Autodesk AutoCAD LT for macOS | >=2022<2022.2 | |
Autodesk AutoCAD LT for macOS | =2020 | |
Autodesk AutoCAD LT for macOS | =2021 | |
Autodesk Design Review 2011 | =2018 | |
Autodesk Design Review 2011 | =2018-hotfix | |
Autodesk Design Review 2011 | =2018-hotfix2 | |
Autodesk Design Review 2011 | =2018-hotfix3 | |
Autodesk Design Review 2011 | =2018-hotfix4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40161 is considered a critical vulnerability due to the potential for code execution through maliciously crafted DLL files.
To fix CVE-2021-40161, update your affected Autodesk software to version 9.0.7 or later.
CVE-2021-40161 affects several versions of Autodesk products including Revit, Navisworks, AutoCAD, and others prior to specific versions.
CVE-2021-40161 enables a memory corruption attack that can lead to remote code execution.
There are no confirmed workarounds for CVE-2021-40161; the best course of action is to apply the necessary updates.