
Mitigation instructions for Autodesk® Inventor 2021-2019 are available in this Autodesk Knowledge Network article and for Autodesk AutoCAD-based products in this Autodesk Knowledge Network article. Updates are not available for previously supported versions of Autodesk® Inventor and AutoCAD® – versions 2021-2019. As a general best practice, we recommend that customers only open JT files from trusted sources and update to the latest software version. This version of Autodesk Inventor includes security updates that address the JT file vulnerabilities. These security fixes are not included in the updates specific to individual toolsets.Īutodesk highly recommends that customers download and install the latest version of Autodesk® Inventor 2022 Update 2 (version 2022.2), which is available via the Autodesk Desktop App or the Accounts Portal. ** Note: Users of Autodesk Advance Steel, Autodesk Civil 3D, and the specialized toolsets of AutoCAD need to install either the AutoCAD product update(s) listed above or a more recent product version. *Note: Product list table contents subject to change Exploitation of this vulnerability may lead to code execution. This vulnerability can be exploited to execute arbitrary code.Ĥ) CVE-2022-27867 - A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability.

This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Ģ) CVE-2021-40159 - An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.ģ) CVE-2022-25788 - A maliciously crafted JT file in Autodesk AutoCAD 20 may be used to write beyond the allocated buffer while parsing JT files. The details of the vulnerabilities are as follows:ġ) CVE-2021-40158 - A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file.
