CVE-2021-27045
Published on: 09/15/2021 12:00:00 AM UTC
Last Modified on: 09/28/2021 04:32:00 PM UTC
Certain versions of Navisworks from Autodesk contain the following vulnerability:
A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF file. This vulnerability can be exploited to execute arbitrary code.
- CVE-2021-27045 has been assigned by
psi[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Advisories | Autodesk Trust Center | www.autodesk.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Autodesk | Navisworks | 2019 | All | All | All |
Application | Autodesk | Navisworks | 2020 | All | All | All |
Application | Autodesk | Navisworks | 2021 | All | All | All |
Application | Autodesk | Navisworks | 2022 | All | All | All |
- cpe:2.3:a:autodesk:navisworks:2019:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:navisworks:2020:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:navisworks:2021:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:navisworks:2022:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-27045 : A maliciously crafted PDF file in #Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to rea… twitter.com/i/web/status/1… | 2021-09-15 17:07:54 |