CVE-2021-40167

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-119 CWE-125
Summary A malicious crafted dwf file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

01 Jul 2022, 17:25

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*

19 Apr 2022, 21:15

Type Values Removed Values Added
Summary A Memory Corruption Vulnerability may lead to remote code execution through maliciously crafted DWF and TGA files in Autodesk Design Review 2018. A malicious crafted dwf file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

18 Apr 2022, 17:15

Type Values Removed Values Added
Summary A Memory Corruption Vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 and prior may lead to remote code execution through maliciously crafted DWF and TGA files. A Memory Corruption Vulnerability may lead to remote code execution through maliciously crafted DWF and TGA files in Autodesk Design Review 2018.

31 Jan 2022, 21:07

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
References (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 - (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004 - Vendor Advisory
CWE CWE-119
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8

25 Jan 2022, 20:19

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-25 20:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-40167

Mitre link : CVE-2021-40167

CVE.ORG link : CVE-2021-40167


JSON object : View

Products Affected

autodesk

  • design_review
CWE
CWE-125

Out-of-bounds Read