PT-2023-21414 · Autodesk · Autodesk Autocad

Published

2023-04-14

·

Updated

2023-04-20

·

CVE-2023-27914

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD version 2023
Description A maliciously crafted X B file can be used to write beyond the allocated buffer, causing a Stack Buffer Overflow when parsed through Autodesk AutoCAD. This can be leveraged by a malicious actor to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Recommendations For Autodesk AutoCAD version 2023, consider disabling the parsing of X B files until a patch is available to prevent potential exploitation. Restrict access to sensitive data and ensure that the software is used in a context that minimizes the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-27914

Affected Products

Autodesk Autocad