// For flags

CVE-2019-7358

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may cause a heap overflow, resulting in code execution.

Se presenta una vulnerabilidad explotable de desbordamiento de pila en la funcionalidad DXF-parsing en Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P & ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018 y Autodesk Civil 3D 2018. Un archivo DXF especialmente creado puede generar un desbordamiento de pila, lo que resulta en la ejecución de código malicioso.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-02-04 CVE Reserved
  • 2019-04-09 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Autodesk
Search vendor "Autodesk"
Advance Steel
Search vendor "Autodesk" for product "Advance Steel"
2018
Search vendor "Autodesk" for product "Advance Steel" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad
Search vendor "Autodesk" for product "Autocad"
2018
Search vendor "Autodesk" for product "Autocad" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Architecture
Search vendor "Autodesk" for product "Autocad Architecture"
2018
Search vendor "Autodesk" for product "Autocad Architecture" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Electrical
Search vendor "Autodesk" for product "Autocad Electrical"
2018
Search vendor "Autodesk" for product "Autocad Electrical" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Lt
Search vendor "Autodesk" for product "Autocad Lt"
2018
Search vendor "Autodesk" for product "Autocad Lt" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Map 3d
Search vendor "Autodesk" for product "Autocad Map 3d"
2018
Search vendor "Autodesk" for product "Autocad Map 3d" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Mechanical
Search vendor "Autodesk" for product "Autocad Mechanical"
2018
Search vendor "Autodesk" for product "Autocad Mechanical" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Mep
Search vendor "Autodesk" for product "Autocad Mep"
2018
Search vendor "Autodesk" for product "Autocad Mep" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad P\&id
Search vendor "Autodesk" for product "Autocad P\&id"
2018
Search vendor "Autodesk" for product "Autocad P\&id" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Autocad Plant 3d
Search vendor "Autodesk" for product "Autocad Plant 3d"
2018
Search vendor "Autodesk" for product "Autocad Plant 3d" and version "2018"
-
Affected
Autodesk
Search vendor "Autodesk"
Civil 3d
Search vendor "Autodesk" for product "Civil 3d"
2018
Search vendor "Autodesk" for product "Civil 3d" and version "2018"
-
Affected