An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018.
References
Link | Resource |
---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-04-09 13:30
Updated : 2019-04-11 06:45
NVD link : CVE-2019-7361
Mitre link : CVE-2019-7361
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
autodesk
- autocad
- autocad_plant_3d
- autocad_mep
- autocad_electrical
- civil_3d
- autocad_p\&id
- advance_steel
- autocad_map_3d
- autocad_mechanical
- autocad_architecture
- autocad_lt