CVE-2022-41309

HIGH

DesignReview.exe - Memory Corruption

Title source: llm

Description

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-787
Status published

Affected Products (50)

autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_architecture
autodesk/autocad_architecture
autodesk/autocad_architecture
autodesk/autocad_architecture
... and 35 more

Timeline

Published Oct 21, 2022
Tracked Since Feb 18, 2026