CVE-2019-7360

UnknownEPSS 1.64%

Last modified

CVE-2019-7360 is a vulnerability of currently unknown severity. An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution.. EPSS estimates a 1.64% chance of exploitation in the next 30 days.

Description

An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution.

Metrics

EPSS Probability
1.64%

73.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AutodeskAdvance Steel2018
AutodeskAutocad2018
AutodeskAutocad Architecture2018
AutodeskAutocad Electrical2018
AutodeskAutocad Lt2018
AutodeskAutocad Map 3d2018
AutodeskAutocad Mechanical2018
AutodeskAutocad Mep2018
AutodeskAutocad P\&Id2018
AutodeskAutocad Plant 3d2018
AutodeskCivil 3d2018

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-7360?
An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution.
How severe is CVE-2019-7360?
Severity scoring for CVE-2019-7360 is pending analysis. The EPSS model estimates a 1.64% probability of exploitation in the next 30 days.
How do I fix CVE-2019-7360?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-7360?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST