CVE-2022-33889
Published on: Not Yet Published
Last Modified on: 10/05/2022 01:21:00 PM UTC
Certain versions of Autocad from Autodesk contain the following vulnerability:
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.
- CVE-2022-33889 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Advisories | Autodesk Trust Center | www.autodesk.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Autodesk | Autocad | All | All | All | All |
Application | Autodesk | Autocad Advance Steel | All | All | All | All |
Application | Autodesk | Autocad Architecture | All | All | All | All |
Application | Autodesk | Autocad Civil 3d | All | All | All | All |
Application | Autodesk | Autocad Electrical | All | All | All | All |
Application | Autodesk | Autocad Lt | All | All | All | All |
Application | Autodesk | Autocad Map 3d | All | All | All | All |
Application | Autodesk | Autocad Mechanical | All | All | All | All |
Application | Autodesk | Autocad Mep | All | All | All | All |
Application | Autodesk | Autocad Plant 3d | All | All | All | All |
Application | Autodesk | Design Review | All | All | All | All |
Application | Autodesk | Design Review | 2018 | - | All | All |
Application | Autodesk | Design Review | 2018 | hotfix | All | All |
Application | Autodesk | Design Review | 2018 | hotfix2 | All | All |
Application | Autodesk | Design Review | 2018 | hotfix3 | All | All |
Application | Autodesk | Design Review | 2018 | hotfix4 | All | All |
Application | Autodesk | Design Review | 2018 | hotfix5 | All | All |
Application | Autodesk | Design Review | 2018 | hotfix6 | All | All |
- cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:*:*:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:hotfix5:*:*:*:*:*:*:
- cpe:2.3:a:autodesk:design_review:2018:hotfix6:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-33889 : A maliciously crafted GIF or JPEG files when parsed through #Autodesk Design Review 2018, and Auto… twitter.com/i/web/status/1… | 2022-10-03 15:09:03 |
![]() |
CVE-2022-33889 | 2022-10-03 15:38:29 |