Lucene search

K
cve[email protected]CVE-2023-27912
HistoryApr 14, 2023 - 7:15 p.m.

CVE-2023-27912

2023-04-1419:15:08
CWE-125
web.nvd.nist.gov
12
cve-2023-27912
x_b file
autodesk
autocad
out-of-bound read
vulnerability
security
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.1%

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.

Affected configurations

NVD
Node
autodeskautocadRange20232023.1.3
OR
autodeskautocad_advance_steelRange20232023.1.3
OR
autodeskautocad_architectureRange20232023.1.3
OR
autodeskautocad_civil_3dRange20232023.1.3
OR
autodeskautocad_electricalRange20232023.1.3
OR
autodeskautocad_ltRange20232023.1.3
OR
autodeskautocad_map_3dRange20232023.1.3
OR
autodeskautocad_mechanicalRange20232023.1.3
OR
autodeskautocad_mepRange20232023.1.3
OR
autodeskautocad_plant_3dRange20232023.1.3

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Autodesk AutoCAD",
    "versions": [
      {
        "version": "2023",
        "status": "affected"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.1%

Related for CVE-2023-27912