High severity7.8NVD Advisory· Published Oct 7, 2022· Updated Jun 17, 2026
CVE-2021-40166
CVE-2021-40166
Description
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.
Affected products
43- cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*Range: >=2019,<2019.1.4
- cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*Range: >=2019,<2019.1.4
- cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*Range: >=2019,<2019.1.4
- cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*Range: >=2019,<2019.1.4
cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*
- cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*
- cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*
- cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*
cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*range: >=2019,<2019.2.2
- cpe:2.3:a:autodesk:infrastructure_parts_editor:2021:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infrastructure_parts_editor:2022:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:autodesk:infraworks:*:*:*:*:*:*:*:*range: >=2019,<2019.3
- cpe:2.3:a:autodesk:infraworks:2019.3:-:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2019.3:hotfix_1:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2019.3:hotfix_2:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2019.3:hotfix_3:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2020.2:-:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2020.2:hotfix_1:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2020.2:hotfix_2:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2021.2:-:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_1:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_2:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2022.0:-:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2022.0:hotfix_1:*:*:*:*:*:*
- cpe:2.3:a:autodesk:infraworks:2022.1:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:storm_and_sanitary_analysis:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:autodesk:storm_and_sanitary_analysis:*:*:*:*:*:*:*:*range: >=2020,<2020.3.1
- cpe:2.3:a:autodesk:storm_and_sanitary_analysis:2019:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:storm_and_sanitary_analysis:2022:*:*:*:*:*:*:*
- Autodesk/Image Processing componentdescription
Patches
Vulnerability mechanics
References
1- www.autodesk.com/trust/security-advisories/adsk-sa-2021-0011nvdVendor Advisory
News mentions
0No linked articles in our index yet.