CVE-2022-25790

HIGH

Autodesk AutoCAD and Navisworks - Out-of-bounds Write via DWF File Parsing

Title source: llm
STIX 2.1

Description

A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (12)
autodesk/advance_steel 2019 - 2019.1.4
autodesk/autocad 2019 - 2019.1.4
autodesk/autocad 2022 - 2022.2.2
autodesk/autocad_architecture 2019 - 2019.1.4
autodesk/autocad_electrical 2019 - 2019.1.4
autodesk/autocad_lt 2019 - 2019.1.4
autodesk/autocad_map_3d 2019 - 2019.1.4
autodesk/autocad_mechanical 2019 - 2019.1.4
autodesk/autocad_mep 2019 - 2019.1.4
autodesk/autocad_plant_3d 2019 - 2019.1.4
... and 2 more
Published Apr 11, 2022
Tracked Since Feb 18, 2026