7.8

CVE-2022-41310

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AutodeskAutocad Version2019
AutodeskAutocad Version2020
AutodeskAutocad Version2021
AutodeskAutocad Version2022
AutodeskAutocad Version2022 SwPlatformmacos
AutodeskAutocad Version2023
AutodeskAutocad Architecture Version2019
AutodeskAutocad Architecture Version2020
AutodeskAutocad Architecture Version2021
AutodeskAutocad Architecture Version2022
AutodeskAutocad Architecture Version2023
AutodeskAutocad Civil 3d Version2019
AutodeskAutocad Civil 3d Version2020
AutodeskAutocad Civil 3d Version2021
AutodeskAutocad Civil 3d Version2022
AutodeskAutocad Civil 3d Version2023
AutodeskAutocad Electrical Version2019
AutodeskAutocad Electrical Version2020
AutodeskAutocad Electrical Version2021
AutodeskAutocad Electrical Version2022
AutodeskAutocad Electrical Version2023
AutodeskAutocad Lt Version2019
AutodeskAutocad Lt Version2020
AutodeskAutocad Lt Version2021
AutodeskAutocad Lt Version2022
AutodeskAutocad Lt Version2022 SwPlatformmacos
AutodeskAutocad Lt Version2023
AutodeskAutocad Map 3d Version2019
AutodeskAutocad Map 3d Version2020
AutodeskAutocad Map 3d Version2021
AutodeskAutocad Map 3d Version2022
AutodeskAutocad Map 3d Version2023
AutodeskAutocad Mechanical Version2019
AutodeskAutocad Mechanical Version2020
AutodeskAutocad Mechanical Version2021
AutodeskAutocad Mechanical Version2022
AutodeskAutocad Mechanical Version2023
AutodeskAutocad Mep Version2019
AutodeskAutocad Mep Version2020
AutodeskAutocad Mep Version2021
AutodeskAutocad Mep Version2022
AutodeskAutocad Mep Version2023
AutodeskAutocad Plant 3d Version2019
AutodeskAutocad Plant 3d Version2020
AutodeskAutocad Plant 3d Version2021
AutodeskAutocad Plant 3d Version2022
AutodeskAutocad Plant 3d Version2023
AutodeskDesign Review Version2018 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.451
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.