A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.
References
Link | Resource |
---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Jul 2023, 14:10
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-787 CWE-125 |
|
References | (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009 - Vendor Advisory | |
CPE | cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:maya_usd:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:infraworks:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:vred:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:alias:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* |
|
First Time |
Autodesk maya Usd
Autodesk autocad Electrical Autodesk autocad Plant 3d Autodesk navisworks Autodesk vred Autodesk autocad Architecture Autodesk autocad Civil 3d Autodesk inventor Autodesk Autodesk revit Autodesk autocad Map 3d Autodesk autocad Advance Steel Autodesk autocad Mechanical Autodesk alias Autodesk infraworks Autodesk autocad Mep Autodesk autocad Autodesk autocad Lt |
23 Jun 2023, 19:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-23 19:15
Updated : 2023-07-05 14:10
NVD link : CVE-2023-25003
Mitre link : CVE-2023-25003
JSON object : View
Products Affected
autodesk
- revit
- autocad_mechanical
- autocad
- inventor
- vred
- autocad_electrical
- autocad_plant_3d
- navisworks
- autocad_mep
- autocad_map_3d
- infraworks
- autocad_advance_steel
- alias
- maya_usd
- autocad_civil_3d
- autocad_architecture
- autocad_lt