CVE-2021-27032
HIGHAutodesk Licensing Services - Privilege Escalation via Weak Service Permissions
Title source: llmDescription
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and are running under elevated privileges. These weak permissions could allow all users on the operating system to modify the service configuration and take ownership of the service.
References (3)
Core 3
Core References
Product, Vendor Advisory x_refsource_misc
https://knowledge.autodesk.com/search-result/caas/downloads/content/autodesk-licensing-service-download.html
Various Sources x_refsource_misc
https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0002%3B
Vendor Advisory x_refsource_misc
https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0002
Scores
CVSS v3
7.8
EPSS
0.0003
EPSS Percentile
9.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-276
Status
published
Products (1)
autodesk/licensing_services
9.0.1.1462.100
Published
May 28, 2021
Tracked Since
Feb 18, 2026