---
id: CVE-2022-25788
title: >-
  A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write
  beyond the allocated buffer while parsing JT files
summary: >-
  A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write
  beyond the allocated buffer while parsing JT files. This vulnerability can be
  exploited to execute arbitrary code.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: autodesk
product: advance_steel
affected:
  - 'advance_steel >= 2022, < 2022.1.2'
  - 'autocad >= 2022, < 2022.1.2'
  - 'autocad >= 2022, < 2022.2.2'
  - 'autocad_architecture >= 2022, < 2022.1.2'
  - 'autocad_electrical >= 2022, < 2022.1.2'
  - 'autocad_lt >= 2022, < 2022.1.2'
  - 'autocad_lt >= 2022, < 2022.2.2'
  - 'autocad_map_3d >= 2022, < 2022.1.2'
  - 'autocad_mechanical >= 2022, < 2022.1.2'
  - 'autocad_mep >= 2022, < 2022.1.2'
  - 'autocad_plant_3d >= 2022, < 2022.1.2'
  - 'civil_3d >= 2022, < 2022.1.2'
  - 'inventor >= 2022, < 2022.2'
patched:
  - advance_steel 2022.1.2
  - autocad 2022.2.2
  - autocad_architecture 2022.1.2
  - autocad_electrical 2022.1.2
  - autocad_lt 2022.2.2
  - autocad_map_3d 2022.1.2
  - autocad_mechanical 2022.1.2
  - autocad_mep 2022.1.2
  - autocad_plant_3d 2022.1.2
  - civil_3d 2022.1.2
  - inventor 2022.2
published: '2022-04-19'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:44.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-25788'
references:
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002'
    label: psirt@autodesk.com
  - url: 'https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01603
epssPercentile: 0.75085
ingestedAt: '2026-10-08T22:11:53.749Z'
---

## Overview

A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.

## Affected

- `advance_steel >= 2022, < 2022.1.2`
- `autocad >= 2022, < 2022.1.2`
- `autocad >= 2022, < 2022.2.2`
- `autocad_architecture >= 2022, < 2022.1.2`
- `autocad_electrical >= 2022, < 2022.1.2`
- `autocad_lt >= 2022, < 2022.1.2`
- `autocad_lt >= 2022, < 2022.2.2`
- `autocad_map_3d >= 2022, < 2022.1.2`
- `autocad_mechanical >= 2022, < 2022.1.2`
- `autocad_mep >= 2022, < 2022.1.2`
- `autocad_plant_3d >= 2022, < 2022.1.2`
- `civil_3d >= 2022, < 2022.1.2`
- `inventor >= 2022, < 2022.2`

## Remediation

Upgrade past the affected range:

- `advance_steel 2022.1.2`
- `autocad 2022.2.2`
- `autocad_architecture 2022.1.2`
- `autocad_electrical 2022.1.2`
- `autocad_lt 2022.2.2`
- `autocad_map_3d 2022.1.2`
- `autocad_mechanical 2022.1.2`
- `autocad_mep 2022.1.2`
- `autocad_plant_3d 2022.1.2`
- `civil_3d 2022.1.2`
- `inventor 2022.2`
