CVE-2021-40158

HIGH

Autodesk Advance Steel < 2022.1.2 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

References (22)

Core 22
Core References

Scores

CVSS v3 7.8
EPSS 0.0044
EPSS Percentile 63.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (14)
autodesk/advance_steel 2022 - 2022.1.2
autodesk/autocad 2022 - 2022.1.2
autodesk/autocad_architecture 2022 - 2022.1.2
autodesk/autocad_electrical 2022 - 2022.1.2
autodesk/autocad_lt 2022 - 2022.1.2
autodesk/autocad_map_3d 2022 - 2022.1.2
autodesk/autocad_mechanical 2022 - 2022.1.2
autodesk/autocad_mep 2022 - 2022.1.2
autodesk/autocad_plant_3d 2022 - 2022.1.2
autodesk/civil_3d 2022 - 2022.1.2
... and 4 more
Published Jan 25, 2022
Tracked Since Feb 18, 2026