PT-2023-5413 · Autodesk · Autodesk Autocad

Published

2023-08-24

·

Updated

2023-11-30

·

CVE-2023-29076

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD versions 2023 through 2024
Description The issue is related to a memory corruption vulnerability when parsing certain file types, including SLDASM, MODEL, SAT, and CATPART files. This vulnerability can be exploited to execute arbitrary code in the current process. The vulnerability is caused by the lack of size checking on input data when copying the buffer, which can lead to memory corruption.
Recommendations For Autodesk AutoCAD versions 2023 and 2024, update to a version that includes the fix for this issue to prevent memory corruption and potential code execution. As a temporary workaround, consider restricting the parsing of SLDASM, MODEL, SAT, and CATPART files until a patch is available. Avoid using the vulnerable file parsing functions until the issue is resolved.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-06043
CVE-2023-29076
ZDI-23-1432
ZDI-23-1433
ZDI-23-1434
ZDI-23-1435

Affected Products

Autodesk Autocad