CVE-2022-27525: High severity autodesk design review 2011 vulnerability
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27525.
What software is affected by this vulnerability?
The Autodesk Design Review versions 2011, 2012, 2013, 2017, 2018, 2018-Hotfix, 2018-Hotfix2, 2018-Hotfix3, and 2018-Hotfix4 are affected.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is high, with a CVSS score of 7.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by consuming a maliciously crafted .dwf or .pct file through the DesignReview.exe application, which can lead to memory corruption and code execution.
How can I mitigate this vulnerability?
Autodesk recommends updating to a version of Design Review that is not affected by this vulnerability.