2024-11-23 11:10:51 +00:00

313 lines
12 KiB
JSON

{
"id": "CVE-2019-7364",
"sourceIdentifier": "psirt@autodesk.com",
"published": "2019-08-23T20:15:10.690",
"lastModified": "2024-11-21T04:48:06.343",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution."
},
{
"lang": "es",
"value": "Vulnerabilidad de precarga de DLL en las versiones 2017, 2018, 2019 y 2020 de Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D y la versi\u00f3n 2017 de AutoCAD P&ID. Un atacante puede enga\u00f1ar a un usuario para que abra un archivo DWG malicioso que puede aprovechar una vulnerabilidad de precarga de DLL en AutoCAD que puede provocar la ejecuci\u00f3n del c\u00f3digo."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:advance_steel:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "CB72BEDD-3A76-44B8-8192-D4F12C87488D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:advance_steel:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "461B3C59-740C-4530-80DA-23DD38A0EEB7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:advance_steel:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "963B02A8-97DE-4C10-9AE1-3DA4FBC9AF9F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:advance_steel:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "8C4543D1-94E4-4470-91BF-6F3141FD9DAE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "D45E4513-4F91-492F-ABFA-E67EAEB3514C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "4C2610D4-81E7-4B85-9147-C3F24895EDB0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "411DC826-735A-4BEB-84BE-9250F97F612E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "E30E2562-D38E-4764-874E-5B2FCF5639E5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_architecture:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "65CA52C5-9F62-455C-949C-4AE00FDDFA09"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_architecture:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "ECDE64CF-3527-4C9A-9672-E2FA3BCC8B65"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_architecture:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "9275E76C-2A79-462A-A9D3-D0B6BBCDD0CC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_architecture:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "B7DFA12E-48C5-47B9-BD9F-1AFACBF4E1EA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_electrical:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "D93A0DCA-DE9C-4A0E-8EC3-46B1B32D88EB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_electrical:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "FC2B0DF8-8827-4CF2-94F1-D2871FA5095F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_electrical:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "A10DE5AF-1718-4899-9238-CFFDC72D05B7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_electrical:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "E388264D-D2D4-4BE4-9097-8F547D73ABE5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_lt:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "36D3F11C-900E-436C-A628-75CE5218489B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_lt:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "85BF0890-5AE7-46BA-8FD4-667B20081A0C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_lt:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "03682B7E-1CF1-4456-A51F-A6ADFC177935"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_lt:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "371C5F60-4959-40C7-93E1-A01510A95115"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "7773B26C-12D3-4D00-990D-16F6978302A7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "F4C4F749-A0C3-4C25-B5FC-CE3E49AFF8F6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "04E05510-B21B-4DDD-88D7-CEB8963E1AFB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "D4CD010A-FDBC-40F9-95AC-0CD8388B85D1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "A591011C-4E67-497D-89B4-6F32460EEF1F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "E34DF2FB-6A4F-4060-9DE4-EE635D9056E8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "19255CEC-6161-4D44-B87E-52E86DF4FBA7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "7147F378-DFB0-48A8-8B05-8777E1CC7F90"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mep:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "01D7FD7C-B818-4FA1-A845-6721729274EA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mep:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "BA943872-F736-4EC2-8328-9AABCAE08154"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mep:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "3F608B1C-BA96-4EA8-A540-83870262CBC1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_mep:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "7CFAAD19-6248-42CB-B177-EC2E5141A953"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_p\\&id:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "166A2A40-5073-4072-BBF9-5593FA052680"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "15F0D764-62D6-4729-BB98-8C4BEBACD45A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "68F6B255-EE77-48BA-AEEE-9395C85BF274"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "4E536B0D-4C95-4589-981A-2F8A6C4B44DC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "3FBDD3AC-FA00-462F-AA13-5A75B5D50689"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:civil_3d:2017:*:*:*:*:*:*:*",
"matchCriteriaId": "6AAAC86E-4D30-4A33-AC84-57486A7C26D8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:civil_3d:2018:*:*:*:*:*:*:*",
"matchCriteriaId": "2692C0E3-9A82-42BA-A80D-8A0D72FD3164"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:civil_3d:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "7F8A4F1F-0D78-41FB-BB62-4A6164AC0F51"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:autodesk:civil_3d:2020:*:*:*:*:*:*:*",
"matchCriteriaId": "F2A4C41C-E547-4693-8C53-E21A56323D52"
}
]
}
]
}
],
"references": [
{
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002",
"source": "psirt@autodesk.com",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}