7.8

CVE-2019-7362

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Design Review Version 2011
Autodesk ≫ Design Review Version 2012
Autodesk ≫ Design Review Version 2013
Autodesk ≫ Design Review Version 2018
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.24% 0.651
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002
Patch
Vendor Advisory