7.8
CVSSv3

CVE-2021-40159

Published: 25/01/2022 Updated: 16/11/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

This vulnerability allows remote malicious users to execute arbitrary code on affected installations of Autodesk Inventor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

autodesk inventor 2022

autodesk inventor 2021

autodesk inventor 2020

autodesk inventor 2019

autodesk autocad

autodesk autocad architecture

autodesk autocad electrical

autodesk autocad map 3d

autodesk autocad mechanical

autodesk advance steel

autodesk autocad lt

autodesk autocad mep

autodesk autocad plant 3d

autodesk civil 3d