Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r553-v847-23pr

Опубликовано: 22 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A maliciously crafted STP or SLDPRT file when ODXSW_DLL.dll parsed through Autodesk AutoCAD can be used to uninitialized variable. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

A maliciously crafted STP or SLDPRT file when ODXSW_DLL.dll parsed through Autodesk AutoCAD can be used to uninitialized variable. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

EPSS

Процентиль: 84%
0.02174
Низкий

7.5 High

CVSS3

Дефекты

CWE-457
CWE-908

Связанные уязвимости

CVSS3: 7.8
nvd
почти 2 года назад

A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

EPSS

Процентиль: 84%
0.02174
Низкий

7.5 High

CVSS3

Дефекты

CWE-457
CWE-908