Lucene search

K
cve[email protected]CVE-2023-27914
HistoryApr 14, 2023 - 7:15 p.m.

CVE-2023-27914

2023-04-1419:15:09
CWE-787
web.nvd.nist.gov
18
cve-2023-27914
autocad 2023
stack buffer overflow
security vulnerability
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

26.7%

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.

Affected configurations

NVD
Node
autodeskautocadRange20232023.1.3
OR
autodeskautocad_advance_steelRange20232023.1.3
OR
autodeskautocad_architectureRange20232023.1.3
OR
autodeskautocad_civil_3dRange20232023.1.3
OR
autodeskautocad_electricalRange20232023.1.3
OR
autodeskautocad_ltRange20232023.1.3
OR
autodeskautocad_map_3dRange20232023.1.3
OR
autodeskautocad_mechanicalRange20232023.1.3
OR
autodeskautocad_mepRange20232023.1.3
OR
autodeskautocad_plant_3dRange20232023.1.3

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Autodesk AutoCAD",
    "versions": [
      {
        "version": "2023",
        "status": "affected"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

26.7%

Related for CVE-2023-27914