← Vulnerability feed

Vulnerability record · CVE-2022-42945 · published 19 December 2022

CVE-2022-42945: Autodesk dwg trueview uncontrolled search path element vulnerability

Autodesk · Dwg Trueview

DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could result in remote code execution on the target system.

7.8 CVSS 3.1 High EPSS 0.27% · top 83.2% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could result in remote code execution on the target system.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-42945 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-7406Autodesk advance steel vulnerabilityA maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious a…EPSS 0.19%7.8CVE-2026-16463Autodesk advance steel heap-based buffer overflow vulnerabilityA maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…EPSS 0.28%7.8CVE-2025-1276Autodesk advance steel out-of-bounds write vulnerabilityA maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor …EPSS 0.29%7.8CVE-2025-1275Autodesk autocad mechanical heap-based buffer overflow vulnerabilityA maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A maliciou…EPSS 0.38%7.8CVE-2024-9997Autodesk autocad classic buffer overflow vulnerabilityA maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can …EPSS 0.21%7.8CVE-2024-9996Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted DWG file, when parsed in acdb25.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor…EPSS 0.21%7.8CVE-2024-8896Autodesk autocad use of uninitialized resource vulnerabilityA maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious…EPSS 0.20%7.8CVE-2024-9489Autodesk autocad memory buffer overflow vulnerabilityA maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can le…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2022-42945), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.