Autodesk
autodesk
364 CVEs • 74 products
Products (74)
Click to collapseToggle
Products (74)
Click to collapse
CVEs (364)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account.
|
Autodesk users who no longer have an active license for an account can still access cases for that account.
|
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privile...Show more |
1Autodesk 43ds Max NavisworksRevit+1 moreJun 17, 2026 Jun 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. |
A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. |
1Autodesk 17Alias AutocadAutocad Advance Steel+14 moreJun 17, 2026 Jun 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context o...Show more |
1Autodesk 17Alias AutocadAutocad Advance Steel+14 moreJun 17, 2026 Jun 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. |
A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability. |
1Autodesk 17Alias AutocadAutocad Advance Steel+14 moreJun 17, 2026 Jun 23, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution. |
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution. |
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution. |
A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could result in code execution. |
A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in code execution. |
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. |
1Autodesk 1Fbx Software Development Kit Jun 17, 2026 Apr 17, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure. |
A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerability which may result in code execution. |
A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerability which may result in code execution. |
A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution. |