7.8
CVE-2022-33883
- EPSS 0.38%
- Veröffentlicht 03.10.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 07:08:31
- Erkennungen
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Advanced Material Exchange Version 2019
Autodesk ≫ Advanced Material Exchange Version 2021
Autodesk ≫ Moldflow Adviser Version 2019
Autodesk ≫ Moldflow Adviser Version 2021
Autodesk ≫ Moldflow Communicator Version 2019
Autodesk ≫ Moldflow Communicator Version 2021
Autodesk ≫ Moldflow Synergy Version 2019
Autodesk ≫ Moldflow Synergy Version 2021
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.301 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0019