CVE-2021-40160

Description

PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.418

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Autodesk Design Review 2018Windows
Vulnerabilities CVE-2021-40160 are affected in AutoCAD MEP 2022.1.0Windows
Vulnerabilities CVE-2021-40160 are affected in AutoCAD Plant 3D 2022.1.0Windows
Vulnerabilities CVE-2021-40160,CVE-2021-40161,CVE-2022-27871 are affected in Autodesk Revit 2020Windows
Vulnerabilities CVE-2021-40160,CVE-2021-40161,CVE-2022-27871 are affected in Autodesk Revit 2021Windows
Multiple Vulnerabilities are affected in Autodesk Revit 2022Windows
Vulnerabilities CVE-2021-40160 are affected in AutoCAD Architecture 2022.1.0Windows
Vulnerabilities CVE-2021-40160 are affected in AutoCAD Electrical 2022.1.0Windows
Vulnerabilities CVE-2021-40160 are affected in AutoCAD MAP 3D 2022.1.0Windows
Vulnerabilities CVE-2021-40160 are affected in AutoCAD Mechanical 2022.1.0Windows
Vulnerabilities CVE-2021-40160 are affected in Autodesk Advance Steel 2022.1.0Windows
Vulnerabilities CVE-2021-40160 are affected in Autodesk Civil 3D 2022.1.0Windows
Multiple Vulnerabilities are affected in Autodesk Design Review 2018.hotfixWindows
Multiple Vulnerabilities are affected in Autodesk Design Review 2018.hotfix2Windows
Multiple Vulnerabilities are affected in Autodesk Design Review 2018.hotfix3Windows
Vulnerabilities CVE-2021-40160,CVE-2021-40161,CVE-2022-27864,CVE-2022-27866 are affected in Autodesk Design Review 2018.hotfix4Windows
Vulnerabilities CVE-2021-40160,CVE-2021-40161 are affected in Autodesk Navisworks Simulate 2019.5Windows
Vulnerabilities CVE-2021-40160,CVE-2021-40161 are affected in Autodesk Navisworks Simulate 2020.3Windows
Vulnerabilities CVE-2021-40160,CVE-2021-40161 are affected in Autodesk Navisworks Simulate 2021.2Windows
Vulnerabilities CVE-2021-40160 are affected in Autodesk Navisworks Simulate 2022.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234