7.8

CVE-2022-27871

Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk3ds Max Version2021
Autodesk3ds Max Version2022
AutodeskAdvance Steel Version2019
AutodeskAdvance Steel Version2020
AutodeskAdvance Steel Version2021
AutodeskAdvance Steel Version2022
AutodeskAutocad Version2019
AutodeskAutocad Version2020
AutodeskAutocad Version2021
AutodeskAutocad Version2022
AutodeskAutocad Version2022 SwPlatformmacos
AutodeskAutocad Architecture Version2019
AutodeskAutocad Architecture Version2020
AutodeskAutocad Architecture Version2021
AutodeskAutocad Architecture Version2022
AutodeskAutocad Civil 3d Version2019
AutodeskAutocad Civil 3d Version2020
AutodeskAutocad Civil 3d Version2021
AutodeskAutocad Civil 3d Version2022
AutodeskAutocad Electrical Version2019
AutodeskAutocad Electrical Version2020
AutodeskAutocad Electrical Version2021
AutodeskAutocad Electrical Version2022
AutodeskAutocad Lt Version2019
AutodeskAutocad Lt Version2020
AutodeskAutocad Lt Version2021
AutodeskAutocad Lt Version2022
AutodeskAutocad Lt Version2022 SwPlatformmacos
AutodeskAutocad Map 3d Version2019
AutodeskAutocad Map 3d Version2020
AutodeskAutocad Map 3d Version2021
AutodeskAutocad Map 3d Version2022
AutodeskAutocad Mechanical Version2019
AutodeskAutocad Mechanical Version2020
AutodeskAutocad Mechanical Version2021
AutodeskAutocad Mechanical Version2022
AutodeskAutocad Mep Version2019
AutodeskAutocad Mep Version2020
AutodeskAutocad Mep Version2021
AutodeskAutocad Mep Version2022
AutodeskAutocad Plant 3d Version2019
AutodeskAutocad Plant 3d Version2020
AutodeskAutocad Plant 3d Version2021
AutodeskAutocad Plant 3d Version2022
AutodeskDesign Review Version2018 Update-
AutodeskNavisworks Version2019
AutodeskNavisworks Version2020
AutodeskNavisworks Version2022
AutodeskRevit Version2020
AutodeskRevit Version2021
AutodeskRevit Version2022
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.579
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.