CVE-2021-27042

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2021
Last modified:
13/05/2022

Description

A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2019 (including) 2019.1.3 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2020 (including) 2020.1.4 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2021 (including) 2021.1.1 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2022 (including) 2022.0.1 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2019 (including) 2019.1.3 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2020 (including) 2020.1.4 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2021 (including) 2021.1.1 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2022 (including) 2022.0.1 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2019 (including) 2019.1.3 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2020 (including) 2020.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2021 (including) 2021.1.1 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2022 (including) 2022.0.1 (including)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2019 (including) 2019.1.3 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2020 (including) 2020.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2021 (including) 2021.1.1 (excluding)


References to Advisories, Solutions, and Tools