7.8
CVE-2022-41301
- EPSS 0.06%
- Veröffentlicht 03.10.2022 15:15:18
- Zuletzt bearbeitet 21.11.2024 07:23:00
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Subassembly Composer Version >= 2020 < 2020.6.3
Autodesk ≫ Subassembly Composer Version >= 2021 < 2021.3.2
Autodesk ≫ Subassembly Composer Version >= 2022 < 2022.2.1
Autodesk ≫ Subassembly Composer Version >= 2023 < 2023.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.196 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.