First published: Fri Oct 07 2022(Updated: )
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
Autodesk AutoCAD Advance Steel | >=2019<2019.1.4 | |
Autodesk AutoCAD Advance Steel | >=2020<2020.1.5 | |
Autodesk AutoCAD Advance Steel | >=2021<2021.1.2 | |
Autodesk AutoCAD Advance Steel | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
Autodesk Civil 3D | >=2019<2019.1.4 | |
Autodesk Civil 3D | >=2020<2020.1.5 | |
Autodesk Civil 3D | >=2021<2021.1.2 | |
Autodesk Civil 3D | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD LT | >=2019<2019.1.4 | |
AutoCAD LT | >=2020<2020.1.5 | |
Autodesk AutoCAD LT for macOS | >=2020<2020.3.2 | |
AutoCAD LT | >=2021<2021.1.2 | |
Autodesk AutoCAD LT for macOS | >=2021<2021.2.2 | |
AutoCAD LT | >=2022<2022.1.2 | |
Autodesk AutoCAD LT for macOS | >=2022<2022.2.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
Autodesk Design Review 2011 | =2018 | |
Autodesk Design Review 2011 | =2018-hotfix | |
Autodesk Design Review 2011 | =2018-hotfix2 | |
Autodesk Design Review 2011 | =2018-hotfix3 | |
Autodesk DWG TrueView | >=2019<2019.1.4 | |
Autodesk DWG TrueView | >=2020<2020.1.5 | |
Autodesk DWG TrueView | >=2021<2021.1.2 | |
Autodesk DWG TrueView | >=2022<2022.1.1 | |
Autodesk Fusion 360 | >=2.0.10356<2.0.11405 | |
Autodesk Infrastructure Parts Editor | >=2019<2019.2.2 | |
Autodesk Infrastructure Parts Editor | >=2020<2020.0.2 | |
Autodesk Infrastructure Parts Editor | =2021 | |
Autodesk Infrastructure Parts Editor | =2022 | |
Autodesk InfraWorks | >=2019<2019.3 | |
Autodesk InfraWorks | >=2020<2020.2 | |
Autodesk InfraWorks | >=2021<2021.2 | |
Autodesk InfraWorks | =2019.3 | |
Autodesk InfraWorks | =2019.3-hotfix_1 | |
Autodesk InfraWorks | =2019.3-hotfix_2 | |
Autodesk InfraWorks | =2019.3-hotfix_3 | |
Autodesk InfraWorks | =2020.2 | |
Autodesk InfraWorks | =2020.2-hotfix_1 | |
Autodesk InfraWorks | =2020.2-hotfix_2 | |
Autodesk InfraWorks | =2021.2 | |
Autodesk InfraWorks | =2021.2-hotfix_1 | |
Autodesk InfraWorks | =2021.2-hotfix_2 | |
Autodesk InfraWorks | =2022.0 | |
Autodesk InfraWorks | =2022.0-hotfix_1 | |
Autodesk InfraWorks | =2022.1 | |
Autodesk Inventor | >=2019<2019.6 | |
Autodesk Inventor | >=2020<2020.5 | |
Autodesk Inventor | >=2021<2021.4 | |
Autodesk Inventor | >=2022<2022.2 | |
Autodesk Navisworks | >=2019<2019.7 | |
Autodesk Navisworks | >=2020<2020.5 | |
Autodesk Navisworks | >=2021<2021.4 | |
Autodesk Navisworks | >=2022<2022.2 | |
Autodesk Revit Architecture | >=2019<2019.2.4 | |
Autodesk Revit Architecture | >=2020<2020.2.6 | |
Autodesk Revit Architecture | >=2021<2021.1.5 | |
Autodesk Revit Architecture | =2022 | |
Autodesk Storm and Sanitary Analysis | >=2020<2020.3.1 | |
Autodesk Storm and Sanitary Analysis | >=2021<2021.3.1 | |
Autodesk Storm and Sanitary Analysis | =2019 | |
Autodesk Storm and Sanitary Analysis | =2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40162 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2021-40162, you need to update your Autodesk software to the latest versions or apply the relevant patches provided by Autodesk.
CVE-2021-40162 is associated with maliciously crafted TIF, PICT, TGA, or RLC files.
CVE-2021-40162 affects multiple Autodesk products, including AutoCAD, AutoCAD Civil 3D, and Autodesk Design Review, among others.
Yes, CVE-2021-40162 can be exploited remotely if the malicious files are opened in the affected Autodesk applications.