CVE-2021-40161

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
23/12/2021
Last modified:
08/08/2023

Description

A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2020.2.5 (excluding)
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2021 (including) 2021.1.6 (excluding)
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2022 (including) 2022.1.2 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2019.6 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2020 (including) 2020.4 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2021 (including) 2021.3 (excluding)
cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* 2022 (including) 2022.2 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2019.1.4 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2020 (including) 2020.1.5 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2021 (including) 2021.1.2 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2022 (including) 2022.1.2 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2019.1.4 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2020 (including) 2020.1.5 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2021 (including) 2021.1.2 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2022 (including) 2022.1.2 (excluding)


References to Advisories, Solutions, and Tools