First published: Fri May 12 2023(Updated: )
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.
Credit: psirt@autodesk.com psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk InfraWorks | >=2021.0<2021.2 | |
Autodesk InfraWorks | >=2023.0<2023.1 | |
Autodesk InfraWorks | =2021.2 | |
Autodesk InfraWorks | =2021.2-hotfix_1 | |
Autodesk InfraWorks | =2021.2-hotfix_2 | |
Autodesk InfraWorks | =2021.2-hotfix_3 | |
Autodesk InfraWorks | =2021.2-hotfix_4 | |
Autodesk InfraWorks | =2021.2-hotfix_5 | |
Autodesk InfraWorks | =2021.2-hotfix_6 | |
Autodesk InfraWorks | =2021.2-hotfix_7 | |
Autodesk InfraWorks | =2021.2-hotfix_8 | |
Autodesk InfraWorks | =2021.2-hotfix_9 | |
Autodesk InfraWorks | =2023.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the vulnerability affecting Autodesk InfraWorks is CVE-2023-25005.
The severity of CVE-2023-25005 is high (7.8).
Versions 2021.0 to 2021.2 and versions 2023.0 to 2023.1 of Autodesk InfraWorks are affected by CVE-2023-25005.
CVE-2023-25005 could lead to a resource injection vulnerability.
To fix CVE-2023-25005, it is recommended to update to a patched version of Autodesk InfraWorks.