CVE-2021-40162
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Affected (88)
Products: Autodesk: Autocad, Autocad Advance Steel, Autocad Architecture, Autocad Civil 3d, Autocad Electrical, Autocad Lt, Autocad Map 3d, Autocad Mechanical, Autocad Mep, Autocad Plant 3d, Design Review, Dwg Trueview, Fusion, Infrastructure Parts Editor, Infraworks, Inventor, Navisworks, Revit, Storm And Sanitary Analysis
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| From 2019 to 2019.1.4 | |
| Version 2018 | |
| From 2019 to 2019.1.4 | |
| From 2.0.10356 to 2.0.11405 | |
| From 2019 to 2019.2.2 | |
| From 2019 to 2019.3 | |
| From 2019 to 2019.6 | |
| From 2019 to 2019.7 | |
| From 2019 to 2019.2.4 | |
| From 2020 to 2020.3.1 |
References (2)
Source: psirt@autodesk.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.