Wiz Agents & Workflows are here

CVE-2019-7365
Autodesk Desktop Application vulnerability analysis and mitigation

Overview

DLL preloading vulnerability (CVE-2019-7365) affects Autodesk Desktop Application versions 7.0.16.29 and earlier. The vulnerability allows an attacker to trick a user into downloading a malicious DLL file into the working directory, which can then be leveraged to execute code on the system (Autodesk Advisory, NVD).

Technical details

The vulnerability exists in the Autodesk desktop application (AdAppMgrSvc.exe), which runs with NT AUTHORITY\SYSTEM privileges. The issue stems from a missing DLL call made by an accompanying library, combined with a lack of digital certificate validation. This allows for the loading of arbitrary, unsigned DLLs. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD, ZDNET).

Impact

If exploited, the vulnerability allows an attacker to operate with NT AUTHORITY\SYSTEM privileges, which is the most powerful user in Windows. This enables access to almost every file and process belonging to the user on the computer. The vulnerability can be used for privilege escalation and arbitrary code execution (ZDNET).

Mitigation and workarounds

Autodesk released a patch for CVE-2019-7365 on November 27, 2019. Users are highly recommended to apply the latest update for Autodesk Desktop Application (ADA) by clicking the update button on the application. The vulnerability is fixed in versions after 7.0.16.29 (ZDNET, Autodesk Advisory).

Community reactions

The vulnerability was discovered and reported by SafeBreach Labs in July 2019. Autodesk acknowledged the bug and issued a CVE number, responding with a patch release in November 2019 (SecurityWeek).

Additional resources


SourceThis report was generated using AI

Related Autodesk Desktop Application vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-33882CRITICAL9.8
  • Autodesk Desktop ApplicationAutodesk Desktop Application
  • cpe:2.3:a:autodesk:autodesk_desktop
NoYesOct 03, 2022
CVE-2019-7365HIGH7.8
  • Autodesk Desktop ApplicationAutodesk Desktop Application
  • cpe:2.3:a:autodesk:autodesk_desktop
NoYesDec 03, 2019

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management