CVE-2022-27864

HIGH

Autodesk Design Review - Remote Code Execution via Double Free in PDF Handling

Title source: llm
STIX 2.1

Description

A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0086
EPSS Percentile 75.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (5)
autodesk/design_review 2011
autodesk/design_review 2012
autodesk/design_review 2013
autodesk/design_review 2017
autodesk/design_review 2018 (6 CPE variants)
Published Jul 29, 2022
Tracked Since Feb 18, 2026