A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Design_review | Autodesk | 2011 (including) | 2011 (including) |
| Design_review | Autodesk | 2012 (including) | 2012 (including) |
| Design_review | Autodesk | 2013 (including) | 2013 (including) |
| Design_review | Autodesk | 2017 (including) | 2017 (including) |
| Design_review | Autodesk | 2018 (including) | 2018 (including) |