Lucene search

K
cve[email protected]CVE-2022-27865
HistoryJul 29, 2022 - 8:15 p.m.

CVE-2022-27865

2022-07-2920:15:12
CWE-787
web.nvd.nist.gov
33
3
cve-2022-27865
buffer overflow
designreview.exe
tga file
pcx file
arbitrary code execution

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.4%

A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe application while parsing TGA and PCX files. This vulnerability may be exploited to execute arbitrary code.

Affected configurations

NVD
Node
autodeskdesign_reviewMatch2011-
OR
autodeskdesign_reviewMatch2012-
OR
autodeskdesign_reviewMatch2013-
OR
autodeskdesign_reviewMatch2017-
OR
autodeskdesign_reviewMatch2018-
OR
autodeskdesign_reviewMatch2018hotfix
OR
autodeskdesign_reviewMatch2018hotfix2
OR
autodeskdesign_reviewMatch2018hotfix3
OR
autodeskdesign_reviewMatch2018hotfix4
OR
autodeskdesign_reviewMatch2018hotfix5

CNA Affected

[
  {
    "product": "Autodesk Design Review",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "2018, 2017, 2013, 2012, 2011"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.4%

Related for CVE-2022-27865