7.8

CVE-2022-33886

A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AutodeskAutocad Version >= 2022 < 2022.1.3
AutodeskAutocad Version >= 2023 < 2023.1.1
AutodeskAutocad Advance Steel Version >= 2022 < 2022.1.3
AutodeskAutocad Advance Steel Version >= 2023 < 2023.1.1
AutodeskAutocad Architecture Version >= 2022 < 2022.1.3
AutodeskAutocad Architecture Version >= 2023 < 2023.1.1
AutodeskAutocad Civil 3d Version >= 2022 < 2022.1.3
AutodeskAutocad Civil 3d Version >= 2023 < 2023.1.1
AutodeskAutocad Electrical Version >= 2022 < 2022.1.3
AutodeskAutocad Electrical Version >= 2023 < 2023.1.1
AutodeskAutocad Lt Version >= 2022 < 2022.1.3
AutodeskAutocad Lt Version >= 2023 < 2023.1.1
AutodeskAutocad Map 3d Version >= 2022 < 2022.1.3
AutodeskAutocad Map 3d Version >= 2023 < 2023.1.1
AutodeskAutocad Mechanical Version >= 2022 < 2022.1.3
AutodeskAutocad Mechanical Version >= 2023 < 2023.1.1
AutodeskAutocad Mep Version >= 2022 < 2022.1.3
AutodeskAutocad Mep Version >= 2023 < 2023.1.1
AutodeskAutocad Plant 3d Version >= 2022 < 2022.1.3
AutodeskAutocad Plant 3d Version >= 2023 < 2023.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.197
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.