CVE-2021-27033

HIGH

Autodesk Design Review 2011-2018 - Remote Code Execution via Double Free

Title source: llm
STIX 2.1

Description

A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0089
EPSS Percentile 75.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (5)
autodesk/design_review 2011
autodesk/design_review 2012
autodesk/design_review 2013
autodesk/design_review 2017
autodesk/design_review 2018
Published Jul 09, 2021
Tracked Since Feb 18, 2026