CVE-2022-42935
Autodesk Design Review vulnerability analysis and mitigation

Overview

CVE-2022-42935 is a Remote Code Execution vulnerability discovered in Autodesk Design Review software, disclosed on October 21, 2022. The vulnerability specifically affects the processing of Macintosh Pict (PCT) files in the DesignReview.exe application, where a maliciously crafted file can lead to memory corruption through write access violation (Fortinet Labs, NVD).

Technical details

The vulnerability occurs during the decoding of Macintosh Pict 'PCT' files in Autodesk Design Review. Specifically, the vulnerability is triggered by a malformed PCT file, which causes an Out of Bounds memory write due to an improper bounds check. The vulnerability requires user interaction to exploit, as the target must open a malicious file (Fortinet Labs).

Impact

When successfully exploited, this vulnerability allows attackers to execute arbitrary code within the context of the current process via a crafted PCT file. The severity is considered high due to the potential for remote code execution (Fortinet Labs).

Mitigation and workarounds

Autodesk has released a security hotfix (version 2018 Hotfix 5) to address this vulnerability. Users of Autodesk Design Review 2018 and earlier versions are strongly recommended to download and install the security hotfix via the Autodesk Knowledge Network (Autodesk Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management