CVE Vulnerabilities

CVE-2021-27033

Double Free

Published: Jul 09, 2021 | Modified: Jun 19, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Design_reviewAutodesk2011 (including)2011 (including)
Design_reviewAutodesk2012 (including)2012 (including)
Design_reviewAutodesk2013 (including)2013 (including)
Design_reviewAutodesk2017 (including)2017 (including)
Design_reviewAutodesk2018 (including)2018 (including)

Potential Mitigations

References