← Vulnerability feed

Vulnerability record · CVE-2021-40164 · published 7 October 2022

CVE-2021-40164: Autodesk autocad out-of-bounds write vulnerability

Autodesk · Autocad

A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

7.8 CVSS 3.1 High EPSS 0.94% · top 40.6% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
19Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40164 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29074Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor …EPSS 1.1%9.8CVE-2023-29075Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can …EPSS 1.1%9.8CVE-2023-29076Autodesk autocad memory buffer overflow vulnerabilityA maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabili…EPSS 1.1%9.8CVE-2023-29073Autodesk autocad heap-based buffer overflow vulnerabilityA maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious ac…EPSS 1.1%7.8CVE-2026-7406Autodesk advance steel vulnerabilityA maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious a…EPSS 0.19%7.8CVE-2026-16463Autodesk advance steel heap-based buffer overflow vulnerabilityA maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…EPSS 0.28%7.8CVE-2025-8893Autodesk revit out-of-bounds write vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may …EPSS 0.17%7.8CVE-2025-8894Autodesk autocad plant 3d heap-based buffer overflow vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can l…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2021-40164), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.