Impact
A local attacker who is already on the victim’s machine can run a specially crafted program that injects unauthenticated messages into Autodesk’s installer named pipes. The attacker can change the permissions or ownership of those pipes, giving themselves elevated privileges and potentially compromising the confidentiality, integrity, and availability of the system. This weakness is classified as Incorrect Permission Assignment (CWE-732).
Affected Systems
Autodesk Installer version 2.22.0 is affected according to the Vendor/Name table and the CPE entry for that release.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for a local privilege escalation. Because EPSS is not available and the vulnerability is not listed in CISA KEV, the current exploitation probability is unclear, but the attack remains plausible for an attacker who has local access. The likely attack vector is local execution on the target machine with low user privileges. An attacker would need to run the malicious executable on the target; once executed, the exploit can modify named pipe permissions and inject messages, granting more privileges.
OpenCVE Enrichment