CVE-2022-42945

DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could result in remote code execution on the target system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*

History

21 Nov 2024, 07:25

Type Values Removed Values Added
Summary
  • (es) La versión DWG TrueViewTM 2023 tiene una vulnerabilidad de secuestro de orden de búsqueda de DLL. La explotación exitosa por parte de un atacante malicioso podría resultar en la ejecución remota de código en el sistema de destino.
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0024 - Vendor Advisory () https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0024 - Vendor Advisory

Information

Published : 2022-12-19 16:15

Updated : 2025-04-17 15:15


NVD link : CVE-2022-42945

Mitre link : CVE-2022-42945

CVE.ORG link : CVE-2022-42945


JSON object : View

Products Affected

autodesk

  • dwg_trueview
CWE
CWE-427

Uncontrolled Search Path Element