VYPR
High severity7.8NVD Advisory· Published Apr 11, 2022· Updated Jun 17, 2026

CVE-2022-25790

CVE-2022-25790

Description

A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.

Affected products

15
  • cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • Autodesk/Autocad5 versions
    cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*range: >=2019,<2019.1.4
    • cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*range: >=2022,<2022.2.2
    • cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*range: >=2019,<2019.1.4
    • (no CPE)
    • (no CPE)range: 2022, 2021, 2020, 2019
  • cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
    Range: >=2019,<2019.1.4
  • cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*range: >=2022,<2022.2
    • (no CPE)range: 2022

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.