CVE-2022-42940
HIGHAutodesk Autocad - Out-of-Bounds Write
Title source: ruleDescription
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Scores
CVSS v3
7.8
EPSS
0.0012
EPSS Percentile
30.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-787
Status
published
Affected Products (50)
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_advance_steel
autodesk/autocad_architecture
autodesk/autocad_architecture
autodesk/autocad_architecture
autodesk/autocad_architecture
... and 35 more
Timeline
Published
Oct 21, 2022
Tracked Since
Feb 18, 2026