7.1
CVE-2022-27524
- EPSS 0.37%
- Veröffentlicht 13.04.2022 18:15:14
- Zuletzt bearbeitet 21.11.2024 06:55:52
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Dwg Trueview Version >= 2019 < 2019.1.4
Autodesk ≫ Dwg Trueview Version >= 2020 < 2020.1.5
Autodesk ≫ Dwg Trueview Version >= 2021 < 2021.1.2
Autodesk ≫ Dwg Trueview Version >= 2022 < 2022.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.58 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:P
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.