A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
History

Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the context of the current process.
Title Double Free File Parsing Vulnerability in Autodesk Design Review
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00931}

epss

{'score': 0.00891}


cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-06-19T13:33:30.640Z

Reserved: 2021-02-09T00:00:00.000Z

Link: CVE-2021-27033

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-09T15:15:07.537

Modified: 2026-06-17T03:44:09.793

Link: CVE-2021-27033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.