---
id: CVE-2021-40159
title: >-
  An Information Disclosure vulnerability for JT files in Autodesk Inventor
  2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to
  code execution through maliciously crafted JT files in the context of the
  current proc…
summary: >-
  An Information Disclosure vulnerability for JT files in Autodesk Inventor
  2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to
  code execution through maliciously crafted JT files in the context of the
  current proc…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-200
vendor: autodesk
product: advance_steel
affected:
  - 'advance_steel >= 2022, < 2022.1.2'
  - 'autocad >= 2022, < 2022.1.2'
  - 'autocad_architecture >= 2022, < 2022.1.2'
  - 'autocad_electrical >= 2022, < 2022.1.2'
  - 'autocad_lt >= 2022, < 2022.1.2'
  - 'autocad_map_3d >= 2022, < 2022.1.2'
  - 'autocad_mechanical >= 2022, < 2022.1.2'
  - 'autocad_mep >= 2022, < 2022.1.2'
  - 'autocad_plant_3d >= 2022, < 2022.1.2'
  - 'civil_3d >= 2022, < 2022.1.2'
  - inventor = 2019
  - inventor = 2020
  - inventor = 2021
  - inventor = 2022
patched:
  - advance_steel 2022.1.2
  - autocad 2022.1.2
  - autocad_architecture 2022.1.2
  - autocad_electrical 2022.1.2
  - autocad_lt 2022.1.2
  - autocad_map_3d 2022.1.2
  - autocad_mechanical 2022.1.2
  - autocad_mep 2022.1.2
  - autocad_plant_3d 2022.1.2
  - civil_3d 2022.1.2
published: '2022-01-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:42.020'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-40159'
references:
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-282/'
    label: psirt@autodesk.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-289/'
    label: psirt@autodesk.com
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-282/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-22-289/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02296
epssPercentile: 0.82737
zeroDay: true
ingestedAt: '2026-10-08T22:11:53.745Z'
---

## Overview

An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.

## Affected

- `advance_steel >= 2022, < 2022.1.2`
- `autocad >= 2022, < 2022.1.2`
- `autocad_architecture >= 2022, < 2022.1.2`
- `autocad_electrical >= 2022, < 2022.1.2`
- `autocad_lt >= 2022, < 2022.1.2`
- `autocad_map_3d >= 2022, < 2022.1.2`
- `autocad_mechanical >= 2022, < 2022.1.2`
- `autocad_mep >= 2022, < 2022.1.2`
- `autocad_plant_3d >= 2022, < 2022.1.2`
- `civil_3d >= 2022, < 2022.1.2`
- `inventor = 2019`
- `inventor = 2020`
- `inventor = 2021`
- `inventor = 2022`

## Remediation

Upgrade past the affected range:

- `advance_steel 2022.1.2`
- `autocad 2022.1.2`
- `autocad_architecture 2022.1.2`
- `autocad_electrical 2022.1.2`
- `autocad_lt 2022.1.2`
- `autocad_map_3d 2022.1.2`
- `autocad_mechanical 2022.1.2`
- `autocad_mep 2022.1.2`
- `autocad_plant_3d 2022.1.2`
- `civil_3d 2022.1.2`
