CVE-2022-42936: High severity Autodesk AutoCAD vulnerability
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42936?
CVE-2022-42936 is a vulnerability in Autodesk Autocad and other related software that allows a malicious crafted .dwf or .pct file to cause memory corruption and potential code execution.
What is the severity of CVE-2022-42936?
The severity of CVE-2022-42936 is high, with a CVSS score of 7.8.
Which software versions are affected by CVE-2022-42936?
CVE-2022-42936 affects multiple versions of Autodesk Autocad, including 2019, 2020, 2021, 2022, and 2023, as well as other related software such as Autocad Advance Steel, Autocad Architecture, Autocad Civil 3D, Autocad Electrical, Autocad LT, Autocad Map 3D, Autocad Mechanical, and Autocad MEP.
How can CVE-2022-42936 be exploited?
CVE-2022-42936 can be exploited by consuming a malicious crafted .dwf or .pct file through the DesignReview.exe application, which can lead to memory corruption and potential code execution.
Where can I find more information about CVE-2022-42936?
More information about CVE-2022-42936 can be found on the Autodesk security advisories page at https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004.