← Vulnerability feed

Vulnerability record · CVE-2022-42933 · published 21 October 2022

CVE-2022-42933: Autodesk autocad out-of-bounds write vulnerability

Autodesk · Autocad

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

7.8 CVSS 3.1 High EPSS 0.36% · top 73.3% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-42933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29074Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor …EPSS 1.1%9.8CVE-2023-29075Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can …EPSS 1.1%9.8CVE-2023-29076Autodesk autocad memory buffer overflow vulnerabilityA maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabili…EPSS 1.1%9.8CVE-2023-29073Autodesk autocad heap-based buffer overflow vulnerabilityA maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious ac…EPSS 1.1%7.8CVE-2026-7406Autodesk advance steel vulnerabilityA maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious a…EPSS 0.19%7.8CVE-2026-16463Autodesk advance steel heap-based buffer overflow vulnerabilityA maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…EPSS 0.28%7.8CVE-2025-8893Autodesk revit out-of-bounds write vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may …EPSS 0.17%7.8CVE-2025-8894Autodesk autocad plant 3d heap-based buffer overflow vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can l…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2022-42933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.