Impact
The Autodesk Installer IPC frame parser fails to validate an input‑specified position or offset, allowing a maliciously crafted input to trigger an out‑of‑range substring operation. This flaw can cause the NT AUTHORITY\\SYSTEM service to terminate unexpectedly, resulting in a denial‑of‑service condition. The weakness is a bounds‑checking error (CWE‑1285) that compromises service availability.
Affected Systems
Autodesk Installer version 2.22.0 is affected. No other product or version information is provided.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.5, indicating a moderate severity DoS risk. EPSS is unavailable, so the likelihood of exploitation is unknown but not considered negligible. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to involve manipulating the installer’s IPC channel, potentially requiring local or remote delivery of crafted input. If exploited, the system would experience an abrupt termination of a SYSTEM‑level service, disrupting operational continuity.
OpenCVE Enrichment