Описание
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-27040
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004
- https://www.zerodayinitiative.com/advisories/ZDI-21-1236
- https://www.zerodayinitiative.com/advisories/ZDI-21-1238
- https://www.zerodayinitiative.com/advisories/ZDI-22-378
- https://www.zerodayinitiative.com/advisories/ZDI-22-473
Связанные уязвимости
CVSS3: 3.3
nvd
больше 4 лет назад
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
CVSS3: 8.8
fstec
около 5 лет назад
Уязвимость программного обеспечения для моделирования, проектирования и черчения AutoCAD, связанная с записью данных за пределами буфера, позволяющая нарушителю выполнить произвольный код