Autodesk AutoCAD CVE-2014-0819 Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:65749
Info
Autodesk AutoCAD CVE-2014-0819 Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 65749 |
| Class: | Design Error |
| CVE: |
CVE-2014-0819 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Feb 21 2014 12:00AM |
| Credit: | kaito834 |
| Vulnerable: |
Autodesk AutoCad 2013 |
| Not Vulnerable: |
Autodesk AutoCAD 2014 0 |
Discussion
Autodesk AutoCAD CVE-2014-0819 Insecure Library Loading Arbitrary Code Execution Vulnerability
Autodesk AutoCAD is prone to a vulnerability that lets attackers execute arbitrary code.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the application.
Autodesk AutoCAD 2013 and prior are vulnerable.
Autodesk AutoCAD is prone to a vulnerability that lets attackers execute arbitrary code.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the application.
Autodesk AutoCAD 2013 and prior are vulnerable.
Exploit / POC
Autodesk AutoCAD CVE-2014-0819 Insecure Library Loading Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Autodesk AutoCAD CVE-2014-0819 Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Autodesk AutoCAD CVE-2014-0819 Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Autodesk Homepage (Autodesk)
- Exploiting DLL Hijacking Flaws (hdm)
- More information about the DLL Preloading remote attack vector (Microsoft)
- JVNDB-2014-000020 AutoCAD may insecurely load dynamic libraries (JPCERT)
- Microsoft Security Advisory (2269637) (Microsoft)