CVE-2022-33886
CVE-2022-33886 is a high-severity vulnerability in Autodesk Autocad with a CVSS 3.x base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-755.
Key facts
- Severity: High (CVSS 3.x base score 7.8)
- EPSS exploit prediction: 1% (59th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-755
- Affected product: Autodesk Autocad
- Published:
- Last modified:
Description
A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.
Frequently asked questions
- What is CVE-2022-33886?
- A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.
- How severe is CVE-2022-33886?
- CVE-2022-33886 has a CVSS 3.x base score of 7.8, rated high severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2022-33886 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (59th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-33886?
- CVE-2022-33886 primarily affects Autodesk Autocad. In total, 10 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-33886?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2022-33886 published?
- CVE-2022-33886 was published on 2022-10-03 and last updated on 2026-06-17.
References
Affected products (10)
- cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
More vulnerabilities in Autodesk Autocad
- CVE-2023-29076 — Critical (CVSS 9.8): A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause…
- CVE-2023-29075 — Critical (CVSS 9.8): A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds…
- CVE-2023-29074 — Critical (CVSS 9.8): A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an…
- CVE-2023-29073 — Critical (CVSS 9.8): A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based…
- CVE-2026-16463 — High (CVSS 7.8): A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A…
- CVE-2025-8894 — High (CVSS 7.8): A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow…
All CVEs affecting Autodesk Autocad →
Other CWE-755 (Improper Handling of Exceptional Conditions) vulnerabilities
- CVE-2025-34193 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior…
- CVE-2025-10156 — Critical (CVSS 9.8): An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314…
- CVE-2022-48673 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in…
- CVE-2024-26584 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto…
- CVE-2021-42142 — Critical (CVSS 9.8): An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a…
- CVE-2021-42141 — Critical (CVSS 9.8): An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with…
Browse all CWE-755 (Improper Handling of Exceptional Conditions) vulnerabilities →