CVE-2022-27864
HIGHAutodesk Design Review - Remote Code Execution via Double Free in PDF Handling
Title source: llmDescription
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0009
Scores
CVSS v3
8.8
EPSS
0.0086
EPSS Percentile
75.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-415
Status
published
Products (5)
autodesk/design_review
2011
autodesk/design_review
2012
autodesk/design_review
2013
autodesk/design_review
2017
autodesk/design_review
2018 (6 CPE variants)
Published
Jul 29, 2022
Tracked Since
Feb 18, 2026