Vulnerability Details CVE-2023-25005
A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.5%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-25005
-
cpe:2.3:a:autodesk:infraworks:2021.0
-
cpe:2.3:a:autodesk:infraworks:2021.1
-
cpe:2.3:a:autodesk:infraworks:2021.2
-
cpe:2.3:a:autodesk:infraworks:2023.0
-
cpe:2.3:a:autodesk:infraworks:2023.1