CVE-2021-27045
Autodesk Navisworks PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF file. This vulnerability can be exploited to execute arbitrary code.
Un archivo PDF diseñado maliciosamente en Autodesk Navisworks versiones 2019, 2020, 2021, 2022, puede ser forzado a leer más allá de los límites asignados cuando se analiza el archivo PDF. Esta vulnerabilidad puede ser explotada para ejecutar código arbitrario
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autodesk Navisworks. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-09 CVE Reserved
- 2021-09-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0008 | 2021-09-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Autodesk Search vendor "Autodesk" | Navisworks Search vendor "Autodesk" for product "Navisworks" | 2019 Search vendor "Autodesk" for product "Navisworks" and version "2019" | - |
Affected
| ||||||
Autodesk Search vendor "Autodesk" | Navisworks Search vendor "Autodesk" for product "Navisworks" | 2020 Search vendor "Autodesk" for product "Navisworks" and version "2020" | - |
Affected
| ||||||
Autodesk Search vendor "Autodesk" | Navisworks Search vendor "Autodesk" for product "Navisworks" | 2021 Search vendor "Autodesk" for product "Navisworks" and version "2021" | - |
Affected
| ||||||
Autodesk Search vendor "Autodesk" | Navisworks Search vendor "Autodesk" for product "Navisworks" | 2022 Search vendor "Autodesk" for product "Navisworks" and version "2022" | - |
Affected
|