First published: Tue Apr 19 2022(Updated: )
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFTron earlier than 9.0.7 version in Autodesk Navisworks 2022, and 2020.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Navisworks | >=2019<2019.6 | |
Autodesk Navisworks | >=2020<2020.4 | |
Autodesk Navisworks | >=2021<2021.3 | |
Autodesk Navisworks | >=2022<2022.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27527 is a Memory Corruption vulnerability that may lead to code execution through maliciously crafted DLL files.
Autodesk Navisworks versions 2019 to 2022.2 are affected by CVE-2022-27527.
CVE-2022-27527 has a severity rating of 7.8 (High).
To fix CVE-2022-27527, upgrade to a version of Autodesk Navisworks earlier than 9.0.7 if using version 2020 or 2022, or apply the necessary security patch provided by Autodesk.
More information about CVE-2022-27527 can be found in the security advisory published by Autodesk: [link](https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010).