CVE-2019-7364

UnknownEPSS 1.89%

Last modified

CVE-2019-7364 is a vulnerability of currently unknown severity. DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.. EPSS estimates a 1.89% chance of exploitation in the next 30 days.

Description

DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.

Metrics

EPSS Probability
1.89%

76.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AutodeskAdvance Steel2017
AutodeskAdvance Steel2018
AutodeskAdvance Steel2019
AutodeskAdvance Steel2020
AutodeskAutocad2017
AutodeskAutocad2018
AutodeskAutocad2019
AutodeskAutocad2020
AutodeskAutocad Architecture2017
AutodeskAutocad Architecture2018
AutodeskAutocad Architecture2019
AutodeskAutocad Architecture2020
AutodeskAutocad Electrical2017
AutodeskAutocad Electrical2018
AutodeskAutocad Electrical2019
AutodeskAutocad Electrical2020
AutodeskAutocad Lt2017
AutodeskAutocad Lt2018
AutodeskAutocad Lt2019
AutodeskAutocad Lt2020
AutodeskAutocad Map 3d2017
AutodeskAutocad Map 3d2018
AutodeskAutocad Map 3d2019
AutodeskAutocad Map 3d2020
AutodeskAutocad Mechanical2017
AutodeskAutocad Mechanical2018
AutodeskAutocad Mechanical2019
AutodeskAutocad Mechanical2020
AutodeskAutocad Mep2017
AutodeskAutocad Mep2018
AutodeskAutocad Mep2019
AutodeskAutocad Mep2020
AutodeskAutocad P\&Id2017
AutodeskAutocad Plant 3d2017
AutodeskAutocad Plant 3d2018
AutodeskAutocad Plant 3d2019
AutodeskAutocad Plant 3d2020
AutodeskCivil 3d2017
AutodeskCivil 3d2018
AutodeskCivil 3d2019
AutodeskCivil 3d2020

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-7364?
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.
How severe is CVE-2019-7364?
Severity scoring for CVE-2019-7364 is pending analysis. The EPSS model estimates a 1.89% probability of exploitation in the next 30 days.
How do I fix CVE-2019-7364?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-7364?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST