First published: Mon Apr 11 2022(Updated: )
A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Navisworks | >=2022<2022.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27528 is a use-after-free vulnerability in Autodesk Navisworks 2022 triggered by maliciously crafted DWFX and SKP files.
Exploitation of CVE-2022-27528 can lead to code execution.
CVE-2022-27528 has a severity score of 7.8 (high).
Autodesk Navisworks 2022 (version 2022.2 and earlier) is affected by CVE-2022-27528.
To fix CVE-2022-27528, apply the latest security update provided by Autodesk.