First published: Mon Apr 11 2022(Updated: )
A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Advance Steel | >=2019<2019.1.4 | |
Autodesk Advance Steel | >=2020<2020.1.5 | |
Autodesk Advance Steel | >=2021<2021.1.2 | |
Autodesk Advance Steel | >=2022<2022.1.2 | |
Autodesk Autocad | >=2019<2019.1.4 | |
Autodesk Autocad | >=2020<2020.1.5 | |
Autodesk Autocad | >=2021<2021.1.2 | |
Autodesk Autocad | >=2022<2022.1.2 | |
Autodesk Autocad | >=2022<2022.2.2 | |
Autodesk AutoCAD Architecture | >=2019<2019.1.4 | |
Autodesk AutoCAD Architecture | >=2020<2020.1.5 | |
Autodesk AutoCAD Architecture | >=2021<2021.1.2 | |
Autodesk AutoCAD Architecture | >=2022<2022.1.2 | |
Autodesk AutoCAD Electrical | >=2019<2019.1.4 | |
Autodesk AutoCAD Electrical | >=2020<2020.1.5 | |
Autodesk AutoCAD Electrical | >=2021<2021.1.2 | |
Autodesk AutoCAD Electrical | >=2022<2022.1.2 | |
Autodesk Autocad Lt | >=2019<2019.1.4 | |
Autodesk Autocad Lt | >=2020<2020.1.5 | |
Autodesk Autocad Lt | >=2021<2021.1.2 | |
Autodesk Autocad Lt | >=2022<2022.1.2 | |
Autodesk AutoCAD Map 3D | >=2019<2019.1.4 | |
Autodesk AutoCAD Map 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Map 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Map 3D | >=2022<2022.1.2 | |
Autodesk AutoCAD Mechanical | >=2019<2019.1.4 | |
Autodesk AutoCAD Mechanical | >=2020<2020.1.5 | |
Autodesk AutoCAD Mechanical | >=2021<2021.1.2 | |
Autodesk AutoCAD Mechanical | >=2022<2022.1.2 | |
Autodesk AutoCAD MEP | >=2019<2019.1.4 | |
Autodesk AutoCAD MEP | >=2020<2020.1.5 | |
Autodesk AutoCAD MEP | >=2021<2021.1.2 | |
Autodesk AutoCAD MEP | >=2022<2022.1.2 | |
Autodesk AutoCAD Plant 3D | >=2019<2019.1.4 | |
Autodesk AutoCAD Plant 3D | >=2020<2020.1.5 | |
Autodesk AutoCAD Plant 3D | >=2021<2021.1.2 | |
Autodesk AutoCAD Plant 3D | >=2022<2022.1.2 | |
Autodesk Civil 3D | >=2019<2019.1.4 | |
Autodesk Civil 3D | >=2020<2020.1.5 | |
Autodesk Civil 3D | >=2021<2021.1.2 | |
Autodesk Civil 3D | >=2022<2022.1.2 | |
Autodesk Navisworks | >=2022<2022.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25792 is a vulnerability that allows a maliciously crafted DXF file to be used to write beyond the allocated buffer in Autodesk AutoCAD 2022, 2021, 2020, 2019, and Autodesk Navisworks 2022, potentially allowing for the execution of arbitrary code.
Autodesk Advance Steel (2019.1.4 - 2022.1.2) and Autodesk AutoCAD (2019.1.4 - 2022.2.2) are affected by CVE-2022-25792.
The severity of CVE-2022-25792 is rated as high, with a CVSS score of 7.8.
CVE-2022-25792 can be exploited by using a maliciously crafted DXF file in Autodesk AutoCAD or Autodesk Navisworks to write beyond the allocated buffer, potentially leading to the execution of arbitrary code.
To mitigate CVE-2022-25792, it is recommended to install the latest security updates provided by Autodesk for the affected software versions.