CVE-2022-25790: High severity autodesk autocad advance steel vulnerability
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-25790.
Which software versions are affected by this vulnerability?
This vulnerability affects Autodesk AutoCAD 2022, 2021, 2020, and 2019, as well as Autodesk Navisworks 2022.
What is the severity of CVE-2022-25790?
The severity of CVE-2022-25790 is high, with a severity value of 7.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by using a maliciously crafted DWF file that allows writing beyond the allocated boundaries when parsing DWF files, potentially leading to code execution.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Autodesk Security Advisory page: [Autodesk Security Advisory](https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005).