Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-27872

Опубликовано: 21 июн. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:autodesk:navisworks:2022:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00418
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-755

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.

EPSS

Процентиль: 61%
0.00418
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-755