Lucene search

K
cve[email protected]CVE-2021-40165
HistoryOct 07, 2022 - 6:15 p.m.

CVE-2021-40165

2022-10-0718:15:14
CWE-787
web.nvd.nist.gov
29
6
autodesk
image processing
vulnerability
arbitrary code execution
tiff
pict
tga
rlc
cve-2021-40165
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

30.4%

A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

Affected configurations

NVD
Node
autodeskautocadRange20192019.1.4
OR
autodeskautocadRange20202020.1.5
OR
autodeskautocadRange20212021.1.2
OR
autodeskautocadRange20222022.1.2
OR
autodeskautocad_advance_steelRange20192019.1.4
OR
autodeskautocad_advance_steelRange20202020.1.5
OR
autodeskautocad_advance_steelRange20212021.1.2
OR
autodeskautocad_advance_steelRange20222022.1.2
OR
autodeskautocad_architectureRange20192019.1.4
OR
autodeskautocad_architectureRange20202020.1.5
OR
autodeskautocad_architectureRange20212021.1.2
OR
autodeskautocad_architectureRange20222022.1.2
OR
autodeskautocad_civil_3dRange20192019.1.4
OR
autodeskautocad_civil_3dRange20202020.1.5
OR
autodeskautocad_civil_3dRange20212021.1.2
OR
autodeskautocad_civil_3dRange20222022.1.2
OR
autodeskautocad_electricalRange20192019.1.4
OR
autodeskautocad_electricalRange20202020.1.5
OR
autodeskautocad_electricalRange20212021.1.2
OR
autodeskautocad_electricalRange20222022.1.2
OR
autodeskautocad_ltRange20192019.1.4
OR
autodeskautocad_ltRange20202020.1.5
OR
autodeskautocad_ltRange20202020.3.2macos
OR
autodeskautocad_ltRange20212021.1.2
OR
autodeskautocad_ltRange20212021.2.2macos
OR
autodeskautocad_ltRange20222022.1.2
OR
autodeskautocad_ltRange20222022.2.2macos
OR
autodeskautocad_map_3dRange20192019.1.4
OR
autodeskautocad_map_3dRange20202020.1.5
OR
autodeskautocad_map_3dRange20212021.1.2
OR
autodeskautocad_map_3dRange20222022.1.2
OR
autodeskautocad_mechanicalRange20192019.1.4
OR
autodeskautocad_mechanicalRange20202020.1.5
OR
autodeskautocad_mechanicalRange20212021.1.2
OR
autodeskautocad_mechanicalRange20222022.1.2
OR
autodeskautocad_mepRange20192019.1.4
OR
autodeskautocad_mepRange20202020.1.5
OR
autodeskautocad_mepRange20212021.1.2
OR
autodeskautocad_mepRange20222022.1.2
OR
autodeskautocad_plant_3dRange20192019.1.4
OR
autodeskautocad_plant_3dRange20202020.1.5
OR
autodeskautocad_plant_3dRange20212021.1.2
OR
autodeskautocad_plant_3dRange20222022.1.2
OR
autodeskdesign_reviewMatch2018-
OR
autodeskdesign_reviewMatch2018hotfix
OR
autodeskdesign_reviewMatch2018hotfix2
OR
autodeskdesign_reviewMatch2018hotfix3
OR
autodeskdwg_trueviewRange20192019.1.4
OR
autodeskdwg_trueviewRange20202020.1.5
OR
autodeskdwg_trueviewRange20212021.1.2
OR
autodeskdwg_trueviewRange20222022.1.1
OR
autodeskfusionRange2.0.103562.0.11405
OR
autodeskinfrastructure_parts_editorRange20192019.2.2
OR
autodeskinfrastructure_parts_editorRange20202020.0.2
OR
autodeskinfrastructure_parts_editorMatch2021
OR
autodeskinfrastructure_parts_editorMatch2022
OR
autodeskinfraworksRange20192019.3
OR
autodeskinfraworksRange20202020.2
OR
autodeskinfraworksRange20212021.2
OR
autodeskinfraworksMatch2019.3-
OR
autodeskinfraworksMatch2019.3hotfix_1
OR
autodeskinfraworksMatch2019.3hotfix_2
OR
autodeskinfraworksMatch2019.3hotfix_3
OR
autodeskinfraworksMatch2020.2-
OR
autodeskinfraworksMatch2020.2hotfix_1
OR
autodeskinfraworksMatch2020.2hotfix_2
OR
autodeskinfraworksMatch2021.2-
OR
autodeskinfraworksMatch2021.2hotfix_1
OR
autodeskinfraworksMatch2021.2hotfix_2
OR
autodeskinfraworksMatch2022.0-
OR
autodeskinfraworksMatch2022.0hotfix_1
OR
autodeskinfraworksMatch2022.1
OR
autodeskinventorRange20192019.6
OR
autodeskinventorRange20202020.5
OR
autodeskinventorRange20212021.4
OR
autodeskinventorRange20222022.2
OR
autodesknavisworksRange20192019.7
OR
autodesknavisworksRange20202020.5
OR
autodesknavisworksRange20212021.4
OR
autodesknavisworksRange20222022.2
OR
autodeskrevitRange20192019.2.4
OR
autodeskrevitRange20202020.2.6
OR
autodeskrevitRange20212021.1.5
OR
autodeskrevitMatch2022
OR
autodeskstorm_and_sanitary_analysisRange20202020.3.1
OR
autodeskstorm_and_sanitary_analysisRange20212021.3.1
OR
autodeskstorm_and_sanitary_analysisMatch2019
OR
autodeskstorm_and_sanitary_analysisMatch2022

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Revit, Inventor, Infraworks, Navisworks, Fusion, Infrastructure Parts Editors, Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D",
    "versions": [
      {
        "version": "2022, 2021, 2020, 2019",
        "status": "affected"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

30.4%

Related for CVE-2021-40165