A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.
References
Link | Resource |
---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009 | Vendor Advisory |
https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009 - Vendor Advisory |
05 Jul 2023, 14:10
Type | Values Removed | Values Added |
---|---|---|
First Time |
Autodesk autocad Electrical
Autodesk autocad Map 3d Autodesk autocad Plant 3d Autodesk inventor Autodesk autocad Mechanical Autodesk vred Autodesk autocad Autodesk autocad Mep Autodesk autocad Civil 3d Autodesk autocad Architecture Autodesk revit Autodesk autocad Advance Steel Autodesk autocad Lt Autodesk navisworks Autodesk Autodesk alias Autodesk infraworks Autodesk maya Usd |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | (MISC) https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0009 - Vendor Advisory | |
CWE | CWE-787 CWE-125 |
|
CPE | cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:vred:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:alias:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:maya_usd:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:infraworks:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:* |
23 Jun 2023, 19:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-23 19:15
Updated : 2024-11-21 07:48
NVD link : CVE-2023-25003
Mitre link : CVE-2023-25003
CVE.ORG link : CVE-2023-25003
JSON object : View
Products Affected
autodesk
- autocad_advance_steel
- maya_usd
- autocad_civil_3d
- autocad_map_3d
- autocad_mep
- navisworks
- autocad_architecture
- autocad_mechanical
- autocad_electrical
- autocad
- autocad_lt
- vred
- infraworks
- revit
- autocad_plant_3d
- alias
- inventor