Vulnerability Description
A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond the allocated buffer while parsing PDF files. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Autodesk | Dwg Trueview | 2021 |
Related Weaknesses (CWE)
References
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007Vendor Advisory
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007Vendor Advisory
FAQ
What is CVE-2022-25797?
CVE-2022-25797 is a vulnerability with a CVSS score of 7.8 (HIGH). A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond the allocated buffer while parsing PDF files. The vulnerability exists because t...
How severe is CVE-2022-25797?
CVE-2022-25797 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25797?
Check the references section above for vendor advisories and patch information. Affected products include: Autodesk Dwg Trueview.