Autodesk Installer Privilege Escalation Vulnerability
Vulnerability
A privilege escalation vulnerability has been identified in Autodesk Installer versions 2.18 and earlier. This vulnerability allows an attacker with local, low-privilege access to execute code as NT AUTHORITY\SYSTEM. The issue arises from inadequate validation of loaded binaries, enabling the execution of maliciously crafted files with elevated privileges.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to execute code with SYSTEM privileges.
Remediation
Users are advised to update to Autodesk Installer version 2.19 or later. The latest version can be downloaded from the Autodesk Update Utility.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
