PT-2024-7533 · Autodesk · Autodesk Autocad

Published

2024-08-22

·

Updated

2024-11-01

·

CVE-2024-8595

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD (affected versions not specified)
Description The issue is related to a Use-After-Free vulnerability in the libodxdll.dll library when parsing a maliciously crafted MODEL file in Autodesk AutoCAD. This can be exploited by a malicious actor to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process. The vulnerability can allow an attacker to gain unauthorized access to protected information, execute arbitrary code, or cause a denial of service using a specially crafted MODEL file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-08930
CVE-2024-8595
ZDI-24-1432

Affected Products

Autodesk Autocad