CVE-2023-27908: High severity autodesk installer vulnerability
Published Jun 23, 2023
·Updated
A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability.
Affected Software
1 affected component
Autodesk Installer>=1.29.0.90<1.39.0.216
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2023-27908.
2
What is the severity of CVE-2023-27908?
The severity of CVE-2023-27908 is high, with a severity value of 7.8.
3
Which software is affected by CVE-2023-27908?
The Autodesk installer software versions between 1.29.0.90 and 1.39.0.216 are affected by CVE-2023-27908.
4
What is the risk associated with CVE-2023-27908?
CVE-2023-27908 poses a Privilege Escalation vulnerability, allowing an attacker to gain elevated privileges.
5
How can I mitigate the impact of CVE-2023-27908?
To mitigate the impact of CVE-2023-27908, it is recommended to update the Autodesk installer software to a version that includes the necessary security patches.