First published: Wed Apr 13 2022(Updated: )
A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through maliciously crafted DWG files.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Autocad | <2019.1.4 | |
Autodesk Autocad | >=2020<2020.1.5 | |
Autodesk Autocad | >=2021<2021.1.2 | |
Autodesk Autocad | >=2022<2022.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25795 is a memory corruption vulnerability in Autodesk TrueView 2022 and 2021 that may lead to remote code execution through maliciously crafted DWG files.
CVE-2022-25795 has a severity rating of 7.8 (high).
Versions up to 2019.1.4, 2020 (up to 2020.1.5), 2021 (up to 2021.1.2), and 2022 (up to 2022.1.2) of Autodesk Autocad are affected by CVE-2022-25795.
The memory corruption vulnerability in Autodesk TrueView 2022 and 2021 can be exploited by using maliciously crafted DWG files.
You can find more information about CVE-2022-25795 in the security advisories released by Autodesk: [link1](https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010) and [link2](https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007).