Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40167

Опубликовано: 25 янв. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00418
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.8
github
около 4 лет назад

A Memory Corruption Vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 and prior may lead to remote code execution through maliciously crafted DWF and TGA files.

EPSS

Процентиль: 61%
0.00418
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-125