First published: Mon Oct 03 2022(Updated: )
A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 | |
Autodesk AutoCAD Advance Steel | >=2022<2022.1.3 | |
Autodesk AutoCAD Advance Steel | >=2023<2023.1.1 | |
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 | |
Autodesk Civil 3D | >=2022<2022.1.3 | |
Autodesk Civil 3D | >=2023<2023.1.1 | |
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 | |
AutoCAD LT | >=2022<2022.1.3 | |
AutoCAD LT | >=2023<2023.1.1 | |
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 | |
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 | |
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 | |
AutoCAD | >=2022<2022.1.3 | |
AutoCAD | >=2023<2023.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-33885 is high with a CVSS score of 7.8.
Autodesk AutoCAD 2023 and 2022, Autodesk AutoCAD Advance Steel, Autodesk AutoCAD Architecture, Autodesk AutoCAD Civil 3D, Autodesk AutoCAD Electrical, Autodesk AutoCAD LT, Autodesk AutoCAD Map 3D, Autodesk AutoCAD Mechanical, Autodesk AutoCAD MEP, and Autodesk AutoCAD Plant 3D are affected by CVE-2022-33885.
CVE-2022-33885 is a vulnerability that allows a maliciously crafted X_B, CATIA, and PDF file to be used to write beyond the allocated buffer, potentially leading to arbitrary code execution.
CVE-2022-33885 can be exploited by parsing a malicious X_B, CATIA, or PDF file through vulnerable versions of Autodesk AutoCAD, resulting in the execution of arbitrary code.
Yes, Autodesk has released a security advisory (ADSK-SA-2022-0020) that provides information and updates to address CVE-2022-33885.