Lucene search

K
cve[email protected]CVE-2022-33889
HistoryOct 03, 2022 - 3:15 p.m.

CVE-2022-33889

2022-10-0315:15:17
CWE-787
web.nvd.nist.gov
33
8
cve-2022-33889
autodesk design review 2018
autocad 2023
autocad 2022
gif
jpeg
heap buffer overflow
arbitrary code execution
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

28.7%

A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.

Affected configurations

NVD
Node
autodeskautocadRange<2022.1.3
OR
autodeskautocadRange2023.0.02023.1.1
OR
autodeskautocad_advance_steelRange<2022.1.3
OR
autodeskautocad_advance_steelRange2023.0.02023.1.1
OR
autodeskautocad_architectureRange<2022.1.3
OR
autodeskautocad_architectureRange2023.0.02023.1.1
OR
autodeskautocad_civil_3dRange<2022.1.3
OR
autodeskautocad_civil_3dRange2023.0.02023.1.1
OR
autodeskautocad_electricalRange<2022.1.3
OR
autodeskautocad_electricalRange2023.0.02023.1.1
OR
autodeskautocad_ltRange<2022.1.3
OR
autodeskautocad_ltRange2023.0.02023.1.1
OR
autodeskautocad_map_3dRange<2022.1.3
OR
autodeskautocad_map_3dRange2023.0.02023.1.1
OR
autodeskautocad_mechanicalRange<2022.1.3
OR
autodeskautocad_mechanicalRange2023.0.02023.1.1
OR
autodeskautocad_mepRange<2022.1.3
OR
autodeskautocad_mepRange2023.0.02023.1.1
OR
autodeskautocad_plant_3dRange<2022.1.3
OR
autodeskautocad_plant_3dRange2023.0.02023.1.1
OR
autodeskdesign_reviewRange<2018
OR
autodeskdesign_reviewMatch2018-
OR
autodeskdesign_reviewMatch2018hotfix
OR
autodeskdesign_reviewMatch2018hotfix2
OR
autodeskdesign_reviewMatch2018hotfix3
OR
autodeskdesign_reviewMatch2018hotfix4
OR
autodeskdesign_reviewMatch2018hotfix5
OR
autodeskdesign_reviewMatch2018hotfix6

CNA Affected

[
  {
    "product": "Autodesk® Design Review, Autodesk® Advance Steel, Autodesk® Civil 3D®",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "2018, 2023, 2022"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

28.7%

Related for CVE-2022-33889