VYPR
High severity7.8NVD Advisory· Published Jun 21, 2022· Updated Jun 17, 2026

CVE-2022-27872

CVE-2022-27872

Description

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.

Affected products

3
  • cpe:2.3:a:autodesk:navisworks:2022:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:autodesk:navisworks:2022:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2022

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.