Lucene search

K
nvd[email protected]NVD:CVE-2022-27866
HistoryJul 29, 2022 - 8:15 p.m.

CVE-2022-27866

2022-07-2920:15:12
CWE-125
web.nvd.nist.gov
3
vulnerability
tiff file
designreview.exe
code execution

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.2%

A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocated boundaries when parsing the TIFF file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Affected configurations

Nvd
Node
autodeskdesign_reviewMatch2011-
OR
autodeskdesign_reviewMatch2012-
OR
autodeskdesign_reviewMatch2013-
OR
autodeskdesign_reviewMatch2017-
OR
autodeskdesign_reviewMatch2018-
OR
autodeskdesign_reviewMatch2018hotfix
OR
autodeskdesign_reviewMatch2018hotfix2
OR
autodeskdesign_reviewMatch2018hotfix3
OR
autodeskdesign_reviewMatch2018hotfix4
OR
autodeskdesign_reviewMatch2018hotfix5
VendorProductVersionCPE
autodeskdesign_review2011cpe:2.3:a:autodesk:design_review:2011:-:*:*:*:*:*:*
autodeskdesign_review2012cpe:2.3:a:autodesk:design_review:2012:-:*:*:*:*:*:*
autodeskdesign_review2013cpe:2.3:a:autodesk:design_review:2013:-:*:*:*:*:*:*
autodeskdesign_review2017cpe:2.3:a:autodesk:design_review:2017:-:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:*
autodeskdesign_review2018cpe:2.3:a:autodesk:design_review:2018:hotfix5:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.2%

Related for NVD:CVE-2022-27866