First published: Mon Apr 11 2022(Updated: )
A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD Advance Steel | >=2019<2019.1.4 | |
Autodesk AutoCAD Advance Steel | >=2020<2020.1.5 | |
Autodesk AutoCAD Advance Steel | >=2021<2021.1.2 | |
Autodesk AutoCAD Advance Steel | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
Autodesk AutoCAD LT for macOS | >=2022<2022.2.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD LT | >=2019<2019.1.4 | |
AutoCAD LT | >=2020<2020.1.5 | |
AutoCAD LT | >=2021<2021.1.2 | |
AutoCAD LT | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
Autodesk AutoCAD Civil 3D | >=2019<2019.1.4 | |
Autodesk AutoCAD Civil 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Civil 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Civil 3D | >=2022<2022.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-25789 is high with a severity value of 7.8.
Autodesk Advance Steel versions 2019.1.4 to 2022.1.2 and Autodesk Autocad versions 2019.1.4 to 2022.2.2 are affected by CVE-2022-25789.
CVE-2022-25789 can be exploited by using maliciously crafted DWF, 3DS, and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, and 2019.
Exploiting CVE-2022-25789 may lead to code execution.
To fix CVE-2022-25789, update to the latest version of Autodesk Advance Steel or Autodesk Autocad.