PT-2024-7767 · Autodesk · Autodesk Autocad

Published

2024-02-28

·

Updated

2025-11-13

·

CVE-2024-23158

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk AutoCAD (affected versions not specified)
Description A maliciously crafted IGES file can cause a use-after-free issue when parsed in ASMImport229A.dll through Autodesk applications. This can be leveraged by a malicious actor to cause a crash or execute arbitrary code in the context of the current process. The vulnerability is related to the use of memory after it has been freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-09258
CVE-2024-23158
ZDI-24-798

Affected Products

Autodesk Autocad