PT-2024-7761 · Autodesk · Autodesk Autocad+1

Published

2024-02-14

·

Updated

2025-11-13

·

CVE-2024-23159

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD (affected versions not specified)
Description The issue is related to the parsing of maliciously crafted STP files in the stp aim x64 vc15d.dll library through Autodesk applications. This can lead to the use of uninitialized variables, potentially resulting in code execution in the current process. The vulnerability can be exploited by a remote attacker using a specially crafted STP file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

BDU:2024-09252
CVE-2024-23159
ZDI-24-794

Affected Products

Autodesk Autocad
Stp Aim X64 Vc15D.Dll