Jump to content

Security hole discovered in Autodesk Desktop App


CAD Panacea

Recommended Posts

According to this article, the Autodesk Desktop App, prior to version 7.0.21.x contains a vulnerability to outside attacks.

At least a portion of the Desktop App runs as a service using the “NT AUTHORITY\SYSTEM” account which has global permissions to everything on the system.

Autodesk Desktop App

In summary, it would be possible for an attacker to load an arbitrary DLL as a regular user and execute the code within as a process which is signed by AutoDesk Inc. as NT AUTHORITY\SYSTEM. This article has more details.

If you are running the Autodesk Desktop App, we’d suggest to simply uninstall it. Why? Here are some reasons. If you choose to keep it, then make sure to update it ASAP.

View the full article

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...