CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

autodesk

design_review

41 known vulnerabilities · sorted by CVSS score

CVE-2022-27864
HIGH8.8

A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

autodesk / design_review+9
Network
Published Jul 29, 2022
Page 1 of 3
CVE-2022-27866
HIGH7.8

A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocated boundaries when parsing the TIFF file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / design_review+9
Local
Published Jul 29, 2022
CVE-2022-27865
HIGH7.8

A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe application while parsing TGA and PCX files. This vulnerability may be exploited to execute arbitrary code.

autodesk / design_review+9
Local
Published Jul 29, 2022
CVE-2021-27041
HIGH7.8

A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code

autodesk / advance_steel+46
Local
Published Jun 25, 2021
CVE-2021-27033
HIGH7.8

A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

autodesk / design_review+4
Local
Published Jul 9, 2021
CVE-2022-42942
HIGH7.8

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / autocad+52
Local
Published Oct 21, 2022
CVE-2022-41309
HIGH7.8

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / autocad+52
Local
Published Oct 21, 2022
CVE-2021-40162
HIGH7.8

A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

autodesk / autocad+87
Local
Published Oct 7, 2022
CVE-2019-7363
HIGH7.8

Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerability, which may result in code execution.

autodesk / design_review+3
Local
Published Aug 23, 2019
CVE-2021-40164
HIGH7.8

A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

autodesk / autocad+87
Local
Published Oct 7, 2022
CVE-2021-40165
HIGH7.8

A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.

autodesk / autocad+87
Local
Published Oct 7, 2022
CVE-2022-33889
HIGH7.8

A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.

autodesk / autocad+27
Local
Published Oct 3, 2022
CVE-2021-27035
HIGH7.8

A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA or DWF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / design_review+7
Local
Published Jul 9, 2021
CVE-2021-40167
HIGH7.8

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / design_review
Local
Published Jan 25, 2022
CVE-2022-27525
HIGH7.8

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / design_review+8
Local
Published Apr 18, 2022
CVE-2022-27526
HIGH7.8

A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / design_review+8
Local
Published Apr 18, 2022
CVE-2019-7362
HIGH7.8

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

autodesk / design_review+3
Local
Published Aug 23, 2019
CVE-2021-27038
HIGH7.8

A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a maliciously crafted PDF file. A malicious actor can leverage this to execute arbitrary code.

autodesk / design_review+4
Local
Published Jul 9, 2021
CVE-2021-27036
HIGH7.8

A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while parsing PCX, PDF, PICT, RCL, BMP, PSD or TIFF files. This vulnerability can be exploited to execute arbitrary code

autodesk / design_review+7
Local
Published Jul 9, 2021
CVE-2022-33890
HIGH7.8

A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / autocad+26
Local
Published Oct 3, 2022