CVE-2022-33885: High severity autodesk autocad 2024 vulnerability
A maliciously crafted XB, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33885?
The severity of CVE-2022-33885 is high with a CVSS score of 7.8.
Which software is affected by CVE-2022-33885?
Autodesk AutoCAD 2023 and 2022, Autodesk AutoCAD Advance Steel, Autodesk AutoCAD Architecture, Autodesk AutoCAD Civil 3D, Autodesk AutoCAD Electrical, Autodesk AutoCAD LT, Autodesk AutoCAD Map 3D, Autodesk AutoCAD Mechanical, Autodesk AutoCAD MEP, and Autodesk AutoCAD Plant 3D are affected by CVE-2022-33885.
What is the vulnerability in CVE-2022-33885?
CVE-2022-33885 is a vulnerability that allows a maliciously crafted X_B, CATIA, and PDF file to be used to write beyond the allocated buffer, potentially leading to arbitrary code execution.
How can CVE-2022-33885 be exploited?
CVE-2022-33885 can be exploited by parsing a malicious X_B, CATIA, or PDF file through vulnerable versions of Autodesk AutoCAD, resulting in the execution of arbitrary code.
Is there a fix for CVE-2022-33885?
Yes, Autodesk has released a security advisory (ADSK-SA-2022-0020) that provides information and updates to address CVE-2022-33885.