CVE-2022-33886: High severity autodesk autocad 2024 vulnerability
A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33886?
The severity of CVE-2022-33886 is high.
Which software versions are affected by CVE-2022-33886?
Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022 are affected by CVE-2022-33886.
How can CVE-2022-33886 be exploited?
CVE-2022-33886 can be exploited by using a maliciously crafted MODEL and SLDPRT file to write beyond the allocated buffer.
What is the CWE value for CVE-2022-33886?
The CWE value for CVE-2022-33886 is 755.
Where can I find more information about CVE-2022-33886?
More information about CVE-2022-33886 can be found at the following link: https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0020