CVE-2022-42940

HIGH

Autodesk Autocad - Out-of-Bounds Write

Title source: rule

Description

A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-787
Status published

Affected Products (50)

autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_architecture
autodesk/autocad_architecture
autodesk/autocad_architecture
autodesk/autocad_architecture
... and 35 more

Timeline

Published Oct 21, 2022
Tracked Since Feb 18, 2026