7.8
CVE-2022-33883
- EPSS 0.06%
- Veröffentlicht 03.10.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 07:08:31
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Advanced Material Exchange Version2019
Autodesk ≫ Advanced Material Exchange Version2021
Autodesk ≫ Moldflow Adviser Version2019
Autodesk ≫ Moldflow Adviser Version2021
Autodesk ≫ Moldflow Communicator Version2019
Autodesk ≫ Moldflow Communicator Version2021
Autodesk ≫ Moldflow Synergy Version2019
Autodesk ≫ Moldflow Synergy Version2021
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.184 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.