Lucene search

K
kasperskyKaspersky LabKLA10081
HistoryJul 18, 2013 - 12:00 a.m.

KLA10081 ACE vulnerability in Autodesk

2013-07-1800:00:00
Kaspersky Lab
threats.kaspersky.com
30

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.007

Percentile

80.0%

An unspecified vulnerability was found in Autodesk products. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed DWG file.

Original advisories

Autodesk bulletin

Related products

AutoCAD

AutoDesk-DWG-TrueView

CVE list

CVE-2013-3665 high

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Autodesk AutoCAD versions from 2011 to 2014 (Any edition)Autodesk Dwg TrueView versions from 2011 to 2014

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.007

Percentile

80.0%