A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Autodesk
Autodesk vred |
|
CPEs | cpe:2.3:a:autodesk:vred:2025:*:*:*:*:*:*:* | |
Vendors & Products |
Autodesk
Autodesk vred |
|
Metrics |
ssvc
|
Tue, 05 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution. | |
Title | Autodesk VRED Design Privilege Escalation Vulnerability | |
Weaknesses | CWE-426 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: autodesk
Published: 2024-11-05T20:06:43.521Z
Updated: 2024-11-05T21:45:40.080Z
Reserved: 2024-08-19T21:37:11.389Z
Link: CVE-2024-7995
Vulnrichment
Updated: 2024-11-05T21:45:30.553Z
NVD
Status : Awaiting Analysis
Published: 2024-11-05T20:15:15.423
Modified: 2024-11-06T18:17:17.287
Link: CVE-2024-7995
Redhat
No data.