CVE-2021-40158High· 7.8▾ Abyssal0dayA maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lea…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.6 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.9%
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
advance_steel >= 2022, < 2022.1.2autocad >= 2022, < 2022.1.2autocad_architecture >= 2022, < 2022.1.2autocad_electrical >= 2022, < 2022.1.2autocad_lt >= 2022, < 2022.1.2autocad_map_3d >= 2022, < 2022.1.2autocad_mechanical >= 2022, < 2022.1.2autocad_mep >= 2022, < 2022.1.2autocad_plant_3d >= 2022, < 2022.1.2civil_3d >= 2022, < 2022.1.2inventor >= 2022, < 2022.2inventor = 2019inventor = 2020inventor = 2021Upgrade past the affected range:
advance_steel 2022.1.2autocad 2022.1.2autocad_architecture 2022.1.2autocad_electrical 2022.1.2autocad_lt 2022.1.2autocad_map_3d 2022.1.2autocad_mechanical 2022.1.2autocad_mep 2022.1.2autocad_plant_3d 2022.1.2civil_3d 2022.1.2inventor 2022.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-25788High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files
CVE-2021-40159High· 7.8An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current proc…
CVE-2022-27867High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability
CVE-2026-7405Medium· 5.5A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library
CVE-2025-9460High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability
CVE-2025-9459High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability