First published: Mon Apr 11 2022(Updated: )
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD Advance Steel | >=2019<2019.1.4 | |
Autodesk AutoCAD Advance Steel | >=2020<2020.1.5 | |
Autodesk AutoCAD Advance Steel | >=2021<2021.1.2 | |
Autodesk AutoCAD Advance Steel | >=2022<2022.1.2 | |
Autodesk AutoCAD 2024 | >=2019<2019.1.4 | |
Autodesk AutoCAD 2024 | >=2020<2020.1.5 | |
Autodesk AutoCAD 2024 | >=2021<2021.1.2 | |
Autodesk AutoCAD 2024 | >=2022<2022.1.2 | |
Autodesk AutoCAD LT for macOS | >=2022<2022.2.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD LT | >=2019<2019.1.4 | |
AutoCAD LT | >=2020<2020.1.5 | |
AutoCAD LT | >=2021<2021.1.2 | |
AutoCAD LT | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
AutoCAD | >=2019<2019.1.4 | |
AutoCAD | >=2020<2020.1.5 | |
AutoCAD | >=2021<2021.1.2 | |
AutoCAD | >=2022<2022.1.2 | |
Autodesk AutoCAD Civil 3D | >=2019<2019.1.4 | |
Autodesk AutoCAD Civil 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Civil 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Civil 3D | >=2022<2022.1.2 | |
Autodesk Navisworks | >=2022<2022.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25790.
This vulnerability affects Autodesk AutoCAD 2022, 2021, 2020, and 2019, as well as Autodesk Navisworks 2022.
The severity of CVE-2022-25790 is high, with a severity value of 7.8.
This vulnerability can be exploited by using a maliciously crafted DWF file that allows writing beyond the allocated boundaries when parsing DWF files, potentially leading to code execution.
You can find more information about this vulnerability on the Autodesk Security Advisory page: [Autodesk Security Advisory](https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005).