VYPR
High severity7.8NVD Advisory· Published May 12, 2023· Updated Jun 17, 2026

CVE-2023-25005

CVE-2023-25005

Description

A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.

Affected products

14
  • Autodesk/InfraWorks13 versions
    cpe:2.3:a:autodesk:infraworks:*:*:*:*:*:*:*:*+ 12 more
    • cpe:2.3:a:autodesk:infraworks:*:*:*:*:*:*:*:*range: >=2021.0,<2021.2
    • cpe:2.3:a:autodesk:infraworks:2021.2:-:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_1:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_2:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_3:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_4:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_5:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_6:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_7:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_8:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2021.2:hotfix_9:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:infraworks:2023.1:-:*:*:*:*:*:*
    • (no CPE)range: 2023, 2021
  • Autodesk/InfraWorksdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.