Security Advisory

CVE-2022-27872

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-21 14:23:37
Last updated 2024-08-03 05:41:10
Assigner autodesk
State PUBLISHED

Description

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.