7.8

CVE-2019-7364

DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AutodeskAdvance Steel Version2017
AutodeskAdvance Steel Version2018
AutodeskAdvance Steel Version2019
AutodeskAdvance Steel Version2020
AutodeskAutocad Version2017
AutodeskAutocad Version2018
AutodeskAutocad Version2019
AutodeskAutocad Version2020
AutodeskAutocad Architecture Version2017
AutodeskAutocad Architecture Version2018
AutodeskAutocad Architecture Version2019
AutodeskAutocad Architecture Version2020
AutodeskAutocad Electrical Version2017
AutodeskAutocad Electrical Version2018
AutodeskAutocad Electrical Version2019
AutodeskAutocad Electrical Version2020
AutodeskAutocad Lt Version2017
AutodeskAutocad Lt Version2018
AutodeskAutocad Lt Version2019
AutodeskAutocad Lt Version2020
AutodeskAutocad Map 3d Version2017
AutodeskAutocad Map 3d Version2018
AutodeskAutocad Map 3d Version2019
AutodeskAutocad Map 3d Version2020
AutodeskAutocad Mechanical Version2017
AutodeskAutocad Mechanical Version2018
AutodeskAutocad Mechanical Version2019
AutodeskAutocad Mechanical Version2020
AutodeskAutocad Mep Version2017
AutodeskAutocad Mep Version2018
AutodeskAutocad Mep Version2019
AutodeskAutocad Mep Version2020
AutodeskAutocad P&id Version2017
AutodeskAutocad Plant 3d Version2017
AutodeskAutocad Plant 3d Version2018
AutodeskAutocad Plant 3d Version2019
AutodeskAutocad Plant 3d Version2020
AutodeskCivil 3d Version2017
AutodeskCivil 3d Version2018
AutodeskCivil 3d Version2019
AutodeskCivil 3d Version2020
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.559
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.