Lucene search

K
nvd[email protected]NVD:CVE-2022-27864
HistoryJul 29, 2022 - 8:15 p.m.

CVE-2022-27864

2022-07-2920:15:12
CWE-415
web.nvd.nist.gov
4
cve-2022-27864
remote attackers
arbitrary code
pdf files
user interaction
malicious page
malicious file

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

76.4%

A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Affected configurations

Nvd
Node
autodeskdesign_reviewMatch2011-
OR
autodeskdesign_reviewMatch2012-
OR
autodeskdesign_reviewMatch2013-
OR
autodeskdesign_reviewMatch2017-
OR
autodeskdesign_reviewMatch2018-
OR
autodeskdesign_reviewMatch2018hotfix
OR
autodeskdesign_reviewMatch2018hotfix2
OR
autodeskdesign_reviewMatch2018hotfix3
OR
autodeskdesign_reviewMatch2018hotfix4
OR
autodeskdesign_reviewMatch2018hotfix5
VendorProductVersionCPE
autodeskdesign_review2011cpe:2.3:a:autodesk:design_review:2011:-:*:*:*:*:*:*
autodeskdesign_review2012cpe:2.3:a:autodesk:design_review:2012:-:*:*:*:*:*:*
autodeskdesign_review2013cpe:2.3:a:autodesk:design_review:2013:-:*:*:*:*:*:*
autodeskdesign_review2017cpe:2.3:a:autodesk:design_review:2017:-:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix5:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

76.4%

Related for NVD:CVE-2022-27864