First published: Mon Apr 11 2022(Updated: )
A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Advance Steel | >=2019<2019.1.4 | |
Autodesk Advance Steel | >=2020<2020.1.5 | |
Autodesk Advance Steel | >=2021<2021.1.2 | |
Autodesk Advance Steel | >=2022<2022.1.2 | |
Autodesk Autocad | >=2019<2019.1.4 | |
Autodesk Autocad | >=2020<2020.1.5 | |
Autodesk Autocad | >=2021<2021.1.2 | |
Autodesk Autocad | >=2022<2022.1.2 | |
Autodesk Autocad | >=2022<2022.2.2 | |
Autodesk AutoCAD Architecture | >=2019<2019.1.4 | |
Autodesk AutoCAD Architecture | >=2020<2020.1.5 | |
Autodesk AutoCAD Architecture | >=2021<2021.1.2 | |
Autodesk AutoCAD Architecture | >=2022<2022.1.2 | |
Autodesk AutoCAD Electrical | >=2019<2019.1.4 | |
Autodesk AutoCAD Electrical | >=2020<2020.1.5 | |
Autodesk AutoCAD Electrical | >=2021<2021.1.2 | |
Autodesk AutoCAD Electrical | >=2022<2022.1.2 | |
Autodesk Autocad Lt | >=2019<2019.1.4 | |
Autodesk Autocad Lt | >=2020<2020.1.5 | |
Autodesk Autocad Lt | >=2021<2021.1.2 | |
Autodesk Autocad Lt | >=2022<2022.1.2 | |
Autodesk AutoCAD Map 3D | >=2019<2019.1.4 | |
Autodesk AutoCAD Map 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Map 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Map 3D | >=2022<2022.1.2 | |
Autodesk AutoCAD Mechanical | >=2019<2019.1.4 | |
Autodesk AutoCAD Mechanical | >=2020<2020.1.5 | |
Autodesk AutoCAD Mechanical | >=2021<2021.1.2 | |
Autodesk AutoCAD Mechanical | >=2022<2022.1.2 | |
Autodesk AutoCAD MEP | >=2019<2019.1.4 | |
Autodesk AutoCAD MEP | >=2020<2020.1.5 | |
Autodesk AutoCAD MEP | >=2021<2021.1.2 | |
Autodesk AutoCAD MEP | >=2022<2022.1.2 | |
Autodesk AutoCAD Plant 3D | >=2019<2019.1.4 | |
Autodesk AutoCAD Plant 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Plant 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Plant 3D | >=2022<2022.1.2 | |
Autodesk Civil 3D | >=2019<2019.1.4 | |
Autodesk Civil 3D | >=2020<2020.1.5 | |
Autodesk Civil 3D | >=2021<2021.1.2 | |
Autodesk Civil 3D | >=2022<2022.1.2 | |
Autodesk Navisworks | >=2022<2022.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-25791.
This vulnerability affects Autodesk AutoCAD 2022, 2021, 2020, and 2019, as well as Autodesk Navisworks 2022.
The severity level of CVE-2022-25791 is high with a CVSS score of 7.8.
An attacker can exploit this vulnerability by using maliciously crafted DLL files in DWF and DWFX files.
Yes, Autodesk has released a security advisory with information on how to mitigate this vulnerability.