CVE-2022-25789

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
11/04/2022
Last modified:
19/04/2022

Description

A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2019 (including) 2019.1.4 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2020 (including) 2020.1.5 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2021 (including) 2021.1.2 (excluding)
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* 2022 (including) 2022.1.2 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2019 (including) 2019.1.4 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2020 (including) 2020.1.5 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2021 (including) 2021.1.2 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2022 (including) 2022.1.2 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:* 2022 (including) 2022.2.2 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2019 (including) 2019.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2020 (including) 2020.1.5 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2021 (including) 2021.1.2 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2022 (including) 2022.1.2 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2019 (including) 2019.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2020 (including) 2020.1.5 (excluding)


References to Advisories, Solutions, and Tools