CVE-2023-25005: High severity autodesk infraworks vulnerability
Published May 12, 2023
·Updated
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.
Affected Software
13 affected components
Autodesk InfraWorks>=2021.0<2021.2
Autodesk InfraWorks>=2023.0<2023.1
Autodesk InfraWorks=2021.2
Autodesk InfraWorks=2021.2-hotfix_1
Autodesk InfraWorks=2021.2-hotfix_2
Autodesk InfraWorks=2021.2-hotfix_3
Autodesk InfraWorks=2021.2-hotfix_4
Autodesk InfraWorks=2021.2-hotfix_5
Autodesk InfraWorks=2021.2-hotfix_6
Autodesk InfraWorks=2021.2-hotfix_7
Autodesk InfraWorks=2021.2-hotfix_8
Autodesk InfraWorks=2021.2-hotfix_9
Autodesk InfraWorks=2023.1
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the vulnerability affecting Autodesk InfraWorks?
The vulnerability ID for the vulnerability affecting Autodesk InfraWorks is CVE-2023-25005.
2
What is the severity of CVE-2023-25005?
The severity of CVE-2023-25005 is high (7.8).
3
Which versions of Autodesk InfraWorks are affected by CVE-2023-25005?
Versions 2021.0 to 2021.2 and versions 2023.0 to 2023.1 of Autodesk InfraWorks are affected by CVE-2023-25005.
4
What is the impact of CVE-2023-25005?
CVE-2023-25005 could lead to a resource injection vulnerability.
5
How can I fix CVE-2023-25005?
To fix CVE-2023-25005, it is recommended to update to a patched version of Autodesk InfraWorks.