Lucene search

K
cve[email protected]CVE-2021-40166
HistoryOct 07, 2022 - 6:15 p.m.

CVE-2021-40166

2022-10-0718:15:14
CWE-416
web.nvd.nist.gov
33
6
cve-2021-40166
png file
code execution
autodesk image processing
vulnerability

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

30.4%

A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.

Affected configurations

NVD
Node
autodeskautocadRange20192019.1.4
OR
autodeskautocadRange20202020.1.5
OR
autodeskautocadRange20212021.1.2
OR
autodeskautocadRange20222022.1.2
OR
autodeskautocad_advance_steelRange20192019.1.4
OR
autodeskautocad_advance_steelRange20202020.1.5
OR
autodeskautocad_advance_steelRange20212021.1.2
OR
autodeskautocad_advance_steelRange20222022.1.2
OR
autodeskautocad_architectureRange20192019.1.4
OR
autodeskautocad_architectureRange20202020.1.5
OR
autodeskautocad_architectureRange20212021.1.2
OR
autodeskautocad_architectureRange20222022.1.2
OR
autodeskautocad_civil_3dRange20192019.1.4
OR
autodeskautocad_civil_3dRange20202020.1.5
OR
autodeskautocad_civil_3dRange20212021.1.2
OR
autodeskautocad_civil_3dRange20222022.1.2
OR
autodeskautocad_electricalRange20192019.1.4
OR
autodeskautocad_electricalRange20202020.1.5
OR
autodeskautocad_electricalRange20212021.1.2
OR
autodeskautocad_electricalRange20222022.1.2
OR
autodeskautocad_ltRange20192019.1.4
OR
autodeskautocad_ltRange20202020.1.5
OR
autodeskautocad_ltRange20202020.3.2macos
OR
autodeskautocad_ltRange20212021.1.2
OR
autodeskautocad_ltRange20212021.2.2macos
OR
autodeskautocad_ltRange20222022.1.2
OR
autodeskautocad_ltRange20222022.2.2macos
OR
autodeskautocad_map_3dRange20192019.1.4
OR
autodeskautocad_map_3dRange20202020.1.5
OR
autodeskautocad_map_3dRange20212021.1.2
OR
autodeskautocad_map_3dRange20222022.1.2
OR
autodeskautocad_mechanicalRange20192019.1.4
OR
autodeskautocad_mechanicalRange20202020.1.5
OR
autodeskautocad_mechanicalRange20212021.1.2
OR
autodeskautocad_mechanicalRange20222022.1.2
OR
autodeskautocad_mepRange20192019.1.4
OR
autodeskautocad_mepRange20202020.1.5
OR
autodeskautocad_mepRange20212021.1.2
OR
autodeskautocad_mepRange20222022.1.2
OR
autodeskautocad_plant_3dRange20192019.1.4
OR
autodeskautocad_plant_3dRange20202020.1.5
OR
autodeskautocad_plant_3dRange20212021.1.2
OR
autodeskautocad_plant_3dRange20222022.1.2
OR
autodeskdesign_reviewMatch2018-
OR
autodeskdesign_reviewMatch2018hotfix
OR
autodeskdesign_reviewMatch2018hotfix2
OR
autodeskdesign_reviewMatch2018hotfix3
OR
autodeskdwg_trueviewRange20192019.1.4
OR
autodeskdwg_trueviewRange20202020.1.5
OR
autodeskdwg_trueviewRange20212021.1.2
OR
autodeskdwg_trueviewRange20222022.1.1
OR
autodeskfusionRange2.0.103562.0.11405
OR
autodeskinfrastructure_parts_editorRange20192019.2.2
OR
autodeskinfrastructure_parts_editorRange20202020.0.2
OR
autodeskinfrastructure_parts_editorMatch2021
OR
autodeskinfrastructure_parts_editorMatch2022
OR
autodeskinfraworksRange20192019.3
OR
autodeskinfraworksRange20202020.2
OR
autodeskinfraworksRange20212021.2
OR
autodeskinfraworksMatch2019.3-
OR
autodeskinfraworksMatch2019.3hotfix_1
OR
autodeskinfraworksMatch2019.3hotfix_2
OR
autodeskinfraworksMatch2019.3hotfix_3
OR
autodeskinfraworksMatch2020.2-
OR
autodeskinfraworksMatch2020.2hotfix_1
OR
autodeskinfraworksMatch2020.2hotfix_2
OR
autodeskinfraworksMatch2021.2-
OR
autodeskinfraworksMatch2021.2hotfix_1
OR
autodeskinfraworksMatch2021.2hotfix_2
OR
autodeskinfraworksMatch2022.0-
OR
autodeskinfraworksMatch2022.0hotfix_1
OR
autodeskinfraworksMatch2022.1
OR
autodeskinventorRange20192019.6
OR
autodeskinventorRange20202020.5
OR
autodeskinventorRange20212021.4
OR
autodeskinventorRange20222022.2
OR
autodesknavisworksRange20192019.7
OR
autodesknavisworksRange20202020.5
OR
autodesknavisworksRange20212021.4
OR
autodesknavisworksRange20222022.2
OR
autodeskrevitRange20192019.2.4
OR
autodeskrevitRange20202020.2.6
OR
autodeskrevitRange20212021.1.5
OR
autodeskrevitMatch2022
OR
autodeskstorm_and_sanitary_analysisRange20202020.3.1
OR
autodeskstorm_and_sanitary_analysisRange20212021.3.1
OR
autodeskstorm_and_sanitary_analysisMatch2019
OR
autodeskstorm_and_sanitary_analysisMatch2022

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Revit, Inventor, Infraworks, Navisworks, Fusion, Infrastructure Parts Editors, Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D",
    "versions": [
      {
        "version": "2022, 2021, 2020, 2019",
        "status": "affected"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

30.4%

Related for CVE-2021-40166