CVE-2021-27033

A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*

History

01 Jul 2022, 18:58

Type Values Removed Values Added
References (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 - (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 - Vendor Advisory

18 Apr 2022, 17:15

Type Values Removed Values Added
References
  • {'url': 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003', 'name': 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 -
Summary A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

20 Jul 2021, 17:51

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CWE CWE-415
References (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003 - (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0003 - Vendor Advisory

09 Jul 2021, 15:38

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-09 15:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-27033

Mitre link : CVE-2021-27033

CVE.ORG link : CVE-2021-27033


JSON object : View

Products Affected

autodesk

  • design_review
CWE
CWE-415

Double Free