CVE-2022-42935: High severity Autodesk AutoCAD vulnerability
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-42935.
What is the severity of CVE-2022-42935?
CVE-2022-42935 has a severity rating of 7.8 (High).
Which software is affected by CVE-2022-42935?
Autodesk Autocad (2019, 2020, 2021, 2022, 2023), Autodesk Autocad Advance Steel (2019, 2020, 2021, 2022, 2023), Autodesk AutoCAD Architecture (2019, 2020, 2021, 2022, 2023), Autodesk Autocad Civil 3d (2019, 2020, 2021, 2022, 2023), Autodesk AutoCAD Electrical (2019, 2020, 2021, 2022, 2023), Autodesk Autocad Lt (2019, 2020, 2021, 2022, 2023), Autodesk AutoCAD Map 3D (2019, 2020, 2021, 2022, 2023), Autodesk AutoCAD Mechanical (2019, 2020, 2021, 2022, 2023), Autodesk AutoCAD MEP (2019, 2020, 2021, 2022, 2023), Autodesk AutoCAD Plant 3D (2019, 2020, 2021, 2022, 2023), and Autodesk Design Review (2018).
How does CVE-2022-42935 occur?
CVE-2022-42935 occurs when a malicious crafted .dwf or .pct file is consumed through the DesignReview.exe application, leading to a memory corruption vulnerability with write access violation.
Is code execution possible with CVE-2022-42935?
Yes, code execution in the context of the current process is possible when CVE-2022-42935 is combined with other vulnerabilities.