← Back

CVE-2021-40160

nvd nist
Published: Dec 23, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

Affected (24)

13 products
Revit
Navisworks
Advance Steel
Autocad
Autocad Architecture
Autocad Electrical
Autocad Lt
Autocad Map 3d
Autocad Mechanical
Autocad Mep
Autocad Plant 3d
Civil 3d
Design Review
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2020 to 2020.2.5
From 2021 to 2021.1.4
From 2022 to 2022.1
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2019 to 2019.6
From 2020 to 2020.4
From 2021 to 2021.3
From 2022 to 2022.1
Configuration C
17 vulnerable
Vulnerable SoftwareAffected Versions
From 2022 to 2022.1.1
Autodesk
From 2022 to 2022.1.1
From 2022 to 2022.2
From 2022 to 2022.1.1
From 2022 to 2022.1.1
Autodesk
From 2022 to 2022.1.1
From 2022 to 2022.2
From 2022 to 2022.1.1
From 2022 to 2022.1.1
From 2022 to 2022.1.1
From 2022 to 2022.1.1
From 2022 to 2022.1.1
Autodesk
Version 2018
Version 2018 hotfix2
Version 2018 hotfix3
Version 2018 hotfix4
Version 2018 hotfix

References (2)

Source: psirt@autodesk.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.