Code execution vulnerabilities in Aurodesk Design Review

Обновлено: 03/06/2020
Дата обнаружения
Уровень угрозы

Multiple serious vulnerabilities have been found in Autodesk Design Review. Malicious users can exploit these vulnerabilities to execute arbitrary code.

Below is a complete list of vulnerabilities

  1. Integer overflow can be exploited remotely via a specially designed BMP file;
  2. Buffer overflows can be exploited remotely via a specially designed BMP, FLI, PCX or GIF files.

Technical details

Vulnerability (1) can be triggered via biClrUsed value.

Vulnerability (2) can be triggered via RLE data in BMP or FLI files, encoded scan lines in PCX file or DataSubBlock or GlobalColorTable in GIF file.

Пораженные продукты

Autodesk Design Review versions earlier than 2013 with hotfix 2


If you use older version you must update to 2013 and install hotfix. If you already use 2013 version — install hotfix
Autodesk Design Review 2013
Autodesk Design Review hotfix

Первичный источник обнаружения
Autodesk hotfix note
Оказываемое влияние
Связанные продукты
Autodesk Design Review
