7.8

CVE-2022-25788

A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Advance Steel Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad SwPlatform - Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad SwPlatform macos Version >= 2022 < 2022.2.2
Autodesk ≫ Autocad Architecture Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad Electrical Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad Lt SwPlatform - Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad Lt SwPlatform macos Version >= 2022 < 2022.2.2
Autodesk ≫ Autocad Map 3d Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad Mechanical Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad Mep Version >= 2022 < 2022.1.2
Autodesk ≫ Autocad Plant 3d Version >= 2022 < 2022.1.2
Autodesk ≫ Civil 3d Version >= 2022 < 2022.1.2
Autodesk ≫ Inventor Version >= 2022 < 2022.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.5% 0.712
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002
Vendor Advisory