Design Review
Vendor:
First CVE: Oct 7, 2008 · Active for 17 years
46
Total CVEs
More Total CVEs than 98% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Design Review over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2008
17 years ago
Most Recent CVE
Oct 21, 2022
1,375 days ago
CVE Severity & Scoring
Design Review46 CVEs
93%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local39 (84.8%)
Network2 (4.3%)
Unknown5 (10.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (89.1%)
High0 (0.0%)
Unknown5 (10.9%)
User Interaction
None0 (0.0%)
Unknown5 (10.9%)
Required41 (89.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None41 (89.1%)
Unknown5 (10.9%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4472HIGH The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers | Oct 7, 2008 | 9.3 | 36 | NO | YES |
CVE-2008-4471HIGH Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk De | Oct 7, 2008 | 9.3 | 35 | NO | YES |
CVE-2022-27864HIGH A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is r | Jul 29, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-40164HIGH A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code. | Oct 7, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-40163HIGH A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component. | Oct 7, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-27041HIGH A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code | Jun 25, 2021 | 7.8 | 26 | NO | NO |
CVE-2022-42940HIGH A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerab | Oct 21, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-41306HIGH A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in con | Oct 14, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-40166HIGH A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability ma | Oct 7, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-40165HIGH A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC fil | Oct 7, 2022 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.3% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Design Review
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2018 | 41 | 7.9 | 1.1% | 0 | 0 |
| 2017 | 12 | 7.9 | 1.5% | 0 | 0 |
| 2013 | 16 | 7.8 | 1.8% | 0 | 0 |
| 2012 | 14 | 7.9 | 1.5% | 0 | 0 |
| 2011 | 14 | 7.9 | 1.5% | 0 | 0 |
| 2009 | 2 | 9.3 | 7.3% | 0 | 2 |