PT-2024-19686 · Autodesk · Autodesk Autocad

Published

2024-02-12

·

Updated

2025-01-27

·

CVE-2024-23136

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD (affected versions not specified)
Description A maliciously crafted STP file in ASMKERN228A.dll, when parsed through Autodesk applications, can be used to dereference an untrusted pointer. This issue, combined with other vulnerabilities, could lead to code execution in the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2024-23136
ZDI-24-160

Affected Products

Autodesk Autocad