Search

Find a vulnerability

Search criteria

    2 vulnerabilities found for Design Review by Autodesk

    CVE-2021-27033 (GCVE-0-2021-27033)

    Vulnerability from nvd – Published: 2021-07-09 14:12 – Updated: 2026-06-19 13:33
    VLAI
    Title
    Double Free File Parsing Vulnerability in Autodesk Design Review
    Summary
    A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Design Review Affected: 2018.0.0, 2017.0.0, 2013.0.0, 2012.0.0, 2011.0.0 , < 2018.0.0 (semver)
        cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T20:40:47.208Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Design Review",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2018.0.0",
                  "status": "affected",
                  "version": "2018.0.0, 2017.0.0, 2013.0.0, 2012.0.0, 2011.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process."
                }
              ],
              "value": "A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-44",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-44 Overflow Binary Resource File"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-415",
                  "description": "CWE-415 Double Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-19T13:33:30.640Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Double Free File Parsing Vulnerability in Autodesk Design Review",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2021-27033",
        "datePublished": "2021-07-09T14:12:16.000Z",
        "dateReserved": "2021-02-09T00:00:00.000Z",
        "dateUpdated": "2026-06-19T13:33:30.640Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2021-27033 (GCVE-0-2021-27033)

    Vulnerability from cvelistv5 – Published: 2021-07-09 14:12 – Updated: 2026-06-19 13:33
    VLAI
    Title
    Double Free File Parsing Vulnerability in Autodesk Design Review
    Summary
    A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Design Review Affected: 2018.0.0, 2017.0.0, 2013.0.0, 2012.0.0, 2011.0.0 , < 2018.0.0 (semver)
        cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T20:40:47.208Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:design_review:2018:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2017:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2013:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2012:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:design_review:2011:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Design Review",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2018.0.0",
                  "status": "affected",
                  "version": "2018.0.0, 2017.0.0, 2013.0.0, 2012.0.0, 2011.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process."
                }
              ],
              "value": "A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-44",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-44 Overflow Binary Resource File"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-415",
                  "description": "CWE-415 Double Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-19T13:33:30.640Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Double Free File Parsing Vulnerability in Autodesk Design Review",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2021-27033",
        "datePublished": "2021-07-09T14:12:16.000Z",
        "dateReserved": "2021-02-09T00:00:00.000Z",
        "dateUpdated": "2026-06-19T13:33:30.640Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }