---
id: CVE-2021-40158
title: >-
  A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and
  AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing
  the JT file
summary: >-
  A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and
  AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing
  the JT file. This vulnerability in conjunction with other vulnerabilities
  could lea…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: autodesk
product: advance_steel
affected:
  - 'advance_steel >= 2022, < 2022.1.2'
  - 'autocad >= 2022, < 2022.1.2'
  - 'autocad_architecture >= 2022, < 2022.1.2'
  - 'autocad_electrical >= 2022, < 2022.1.2'
  - 'autocad_lt >= 2022, < 2022.1.2'
  - 'autocad_map_3d >= 2022, < 2022.1.2'
  - 'autocad_mechanical >= 2022, < 2022.1.2'
  - 'autocad_mep >= 2022, < 2022.1.2'
  - 'autocad_plant_3d >= 2022, < 2022.1.2'
  - 'civil_3d >= 2022, < 2022.1.2'
  - 'inventor >= 2022, < 2022.2'
  - inventor = 2019
  - inventor = 2020
  - inventor = 2021
patched:
  - advance_steel 2022.1.2
  - autocad 2022.1.2
  - autocad_architecture 2022.1.2
  - autocad_electrical 2022.1.2
  - autocad_lt 2022.1.2
  - autocad_map_3d 2022.1.2
  - autocad_mechanical 2022.1.2
  - autocad_mep 2022.1.2
  - autocad_plant_3d 2022.1.2
  - civil_3d 2022.1.2
  - inventor 2022.2
published: '2022-01-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:41.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-40158'
references:
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-281/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-283/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-284/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-285/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-286/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-287/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-288/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-441/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-443/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-444/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-445/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-447/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-448/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-449/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-450/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-451/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-452/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-453/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-454/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-455/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-466/'
    label: psirt@autodesk.com
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-281/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-283/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-284/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-285/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-286/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-287/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-288/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-441/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-443/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-444/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-445/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-447/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-448/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-449/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-450/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-451/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-452/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-453/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-454/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-455/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-466/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02885
epssPercentile: 0.86453
zeroDay: true
ingestedAt: '2026-10-08T22:11:53.745Z'
---

## Overview

A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

## Affected

- `advance_steel >= 2022, < 2022.1.2`
- `autocad >= 2022, < 2022.1.2`
- `autocad_architecture >= 2022, < 2022.1.2`
- `autocad_electrical >= 2022, < 2022.1.2`
- `autocad_lt >= 2022, < 2022.1.2`
- `autocad_map_3d >= 2022, < 2022.1.2`
- `autocad_mechanical >= 2022, < 2022.1.2`
- `autocad_mep >= 2022, < 2022.1.2`
- `autocad_plant_3d >= 2022, < 2022.1.2`
- `civil_3d >= 2022, < 2022.1.2`
- `inventor >= 2022, < 2022.2`
- `inventor = 2019`
- `inventor = 2020`
- `inventor = 2021`

## Remediation

Upgrade past the affected range:

- `advance_steel 2022.1.2`
- `autocad 2022.1.2`
- `autocad_architecture 2022.1.2`
- `autocad_electrical 2022.1.2`
- `autocad_lt 2022.1.2`
- `autocad_map_3d 2022.1.2`
- `autocad_mechanical 2022.1.2`
- `autocad_mep 2022.1.2`
- `autocad_plant_3d 2022.1.2`
- `civil_3d 2022.1.2`
- `inventor 2022.2`
