CVE-2023-25005
12.05.2023, 21:15
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
autodesk | infraworks | 2021.0 ≤ 𝑥 < 2021.2 |
autodesk | infraworks | 2023.0 ≤ 𝑥 < 2023.1 |
autodesk | infraworks | 2021.2 |
autodesk | infraworks | 2021.2:hotfix_1 |
autodesk | infraworks | 2021.2:hotfix_2 |
autodesk | infraworks | 2021.2:hotfix_3 |
autodesk | infraworks | 2021.2:hotfix_4 |
autodesk | infraworks | 2021.2:hotfix_5 |
autodesk | infraworks | 2021.2:hotfix_6 |
autodesk | infraworks | 2021.2:hotfix_7 |
autodesk | infraworks | 2021.2:hotfix_8 |
autodesk | infraworks | 2021.2:hotfix_9 |
autodesk | infraworks | 2023.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration