Описание
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability can be exploited to execute arbitrary code
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability can be exploited to execute arbitrary code
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-40158
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002
- https://www.zerodayinitiative.com/advisories/ZDI-22-281
- https://www.zerodayinitiative.com/advisories/ZDI-22-283
- https://www.zerodayinitiative.com/advisories/ZDI-22-284
- https://www.zerodayinitiative.com/advisories/ZDI-22-285
- https://www.zerodayinitiative.com/advisories/ZDI-22-286
- https://www.zerodayinitiative.com/advisories/ZDI-22-287
- https://www.zerodayinitiative.com/advisories/ZDI-22-288
- https://www.zerodayinitiative.com/advisories/ZDI-22-441
- https://www.zerodayinitiative.com/advisories/ZDI-22-443
- https://www.zerodayinitiative.com/advisories/ZDI-22-444
- https://www.zerodayinitiative.com/advisories/ZDI-22-445
- https://www.zerodayinitiative.com/advisories/ZDI-22-447
- https://www.zerodayinitiative.com/advisories/ZDI-22-448
- https://www.zerodayinitiative.com/advisories/ZDI-22-449
- https://www.zerodayinitiative.com/advisories/ZDI-22-450
- https://www.zerodayinitiative.com/advisories/ZDI-22-451
- https://www.zerodayinitiative.com/advisories/ZDI-22-452
- https://www.zerodayinitiative.com/advisories/ZDI-22-453
- https://www.zerodayinitiative.com/advisories/ZDI-22-454
- https://www.zerodayinitiative.com/advisories/ZDI-22-455
- https://www.zerodayinitiative.com/advisories/ZDI-22-466
Связанные уязвимости
CVSS3: 7.8
nvd
около 4 лет назад
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.