CVE-2022-27871: Buffer Overflow
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27871?
CVE-2022-27871 is a vulnerability found in Autodesk AutoCAD product suite, Revit, Design Review, and Navisworks releases using PDFTron prior to version 9.1.17. It allows an attacker to write beyond the allocated buffer while parsing PDF files, potentially leading to the execution of arbitrary code.
Which software versions are affected by CVE-2022-27871?
The affected software versions include Autodesk 3ds Max 2021 and 2022, Autodesk Advance Steel 2019, 2020, 2021, and 2022, Autodesk Autocad 2019, 2020, 2021, and 2022 (including macOS), Autodesk Autocad Architecture 2019, 2020, 2021, and 2022, Autodesk Autocad Civil 3d 2019, 2020, 2021, and 2022, Autodesk AutoCAD Electrical 2019, 2020, 2021, and 2022, Autodesk Autocad LT 2019, 2020, 2021, and 2022 (including macOS), Autodesk AutoCAD Map 3D 2019, 2020, 2021, and 2022, Autodesk AutoCAD Mechanical 2019, 2020, 2021, and 2022, Autodesk AutoCAD MEP 2019, 2020, 2021, and 2022, Autodesk AutoCAD Plant 3D 2019, 2020, 2021, and 2022, Autodesk Design Review 2018, and Autodesk Navisworks 2019, 2020, and 2022.
What is the severity of CVE-2022-27871?
CVE-2022-27871 has a severity rating of 7.8, which is considered high.
How can CVE-2022-27871 be exploited?
CVE-2022-27871 can be exploited by parsing malicious PDF files, which can lead to the execution of arbitrary code.
Is there a fix for CVE-2022-27871?
Yes, upgrading to version 9.1.17 or higher of PDFTron will fix the vulnerability.