Autodesk Design Review 2018 Hotfix 5

Autodesk Support

Jan 24, 2022


Thank you for downloading the Autodesk® Design Review 2018 Hotfix 5. We strongly recommend that you read this document in its entirety before applying the Hotfix to your product. 

Affected Products 

The issues addressed by this hotfix affect Autodesk Design Review 2018, Autodesk Design Review 2013, Autodesk Design Review 2012, and Autodesk Design Review 2011.

Issues 

This hotfix addresses the following security vulnerabilities:

  • Where, upon visiting a malicious page or opening a malicious file, Autodesk Design Review becomes prone to a use after free vulnerability, where a remote attacker could execute arbitrary code when Design Review processes PNG files.
  • Where, upon visiting a malicious page or opening a malicious file, a remote attacker could force Design Review to write outside the bounds of the allocated structure. An attacker could then execute arbitrary code when Design Review processes PDF files.
  • Where a maliciously crafted PDF file can be used to attempt to free an object that has already been freed. An attacker could leverage this vulnerability to execute arbitrary code.
  • Where a maliciously crafted BMP file can be used to force Design Review to write outside the bounds of the allocated structure. An attacker could leverage this vulnerability to execute arbitrary code.
  • Where, upon visiting a malicious page or opening a malicious file, a remote attacker could force Design Review to write outside the bounds of the allocated structure. An attacker could then execute arbitrary code when Design Review processes DWF files.
  • Where a maliciously crafted DWF file or TGA file could cause memory corruption and potentially execute arbitrary code.

Causes

Please see the details in Autodesk Trust Center security advisory: Vulnerabilities in the Autodesk® Design Review Software.

Installation and Execution Instructions

For users of Autodesk Design Review 2018:

  1. Download ADR2018SP5.msp from this page.
  2. In Windows Explorer, right-click ADR2018SP5.msp and select Run as Administrator.

For users of Autodesk Design Review 2013 or earlier:

  1. Uninstall Autodesk Design Review.
  2. Download and install Autodesk Design Review 2018.
  3. Download ADR2018SP5.msp from this page.
  4. In Windows Explorer, right-click ADR2018SP5.msp and select Run as Administrator.


Installation Verification Instructions 

  1. Navigate to the folder Autodesk Design Review has been installed to (C:\Program Files \x86\Autodesk\Autodesk Design Review by default).
  2. Right-click DesignReview.exe and select Properties.
  3. Inspect the Details tab.
  4. Verify that the version is 14.0.5.200.

Note: Autodesk encourages you to use the Autodesk Viewer to view and share 2D and 3D design files over the web. The Autodesk Viewer can handle more than 70 different design file formats.

 

ADR2018SP5.msp (msi - 83.9MB)


Was this information helpful?


Need help? Ask the Autodesk Assistant!

The Assistant can help you find answers or contact an agent.


What level of support do you have?

Different subscription plans provide distinct categories of support. Find out the level of support for your plan.

View levels of support