First published: Tue Jun 21 2022(Updated: )
A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Navisworks | =2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27872 is a vulnerability that allows a maliciously crafted PDF file to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022.
CVE-2022-27872 affects Autodesk Navisworks 2022 by causing an unhandled exception when parsing a crafted PDF file, resulting in a vulnerability that can be exploited by an attacker.
The severity of CVE-2022-27872 is high, with a CVSS score of 7.8.
To fix CVE-2022-27872, it is recommended to update to the latest version of Autodesk Navisworks 2022, which includes a patch for this vulnerability.
More information about CVE-2022-27872 can be found in the Autodesk Security Advisory ADCK-SA-2022-0011.