CVE-2022-27524

EUVD-2022-32025
An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
autodeskdwg_trueview
2019 ≤
𝑥
< 2019.1.4
autodeskdwg_trueview
2020 ≤
𝑥
< 2020.1.5
autodeskdwg_trueview
2021 ≤
𝑥
< 2021.1.2
autodeskdwg_trueview
2022 ≤
𝑥
< 2022.1.2
𝑥
= Vulnerable software versions