CVE-2022-27528: Use After Free
Published Apr 11, 2022
·Updated
A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Affected Software
1 affected component
Autodesk Navisworks>=2022<2022.2
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-27528?
CVE-2022-27528 is a use-after-free vulnerability in Autodesk Navisworks 2022 triggered by maliciously crafted DWFX and SKP files.
2
How can CVE-2022-27528 be exploited?
Exploitation of CVE-2022-27528 can lead to code execution.
3
What is the severity of CVE-2022-27528?
CVE-2022-27528 has a severity score of 7.8 (high).
4
Which version of Autodesk Navisworks is affected by CVE-2022-27528?
Autodesk Navisworks 2022 (version 2022.2 and earlier) is affected by CVE-2022-27528.
5
How can I fix CVE-2022-27528?
To fix CVE-2022-27528, apply the latest security update provided by Autodesk.