Vulnerabilites related to autodesk - civil_3d
CVE-2024-37003 (GCVE-0-2024-37003)
Vulnerability from cvelistv5
Published
2024-06-25 03:12
Modified
2025-01-28 17:12
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-121 - Stack-based Buffer Overflow
Summary
A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37003", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:25:12.539478Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:25:18.240Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.579Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-121", "description": "CWE-121: Stack-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:12:49.483Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37003", "datePublished": "2024-06-25T03:12:13.660Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:12:49.483Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23142 (GCVE-0-2024-23142)
Vulnerability from cvelistv5
Published
2024-06-25 01:24
Modified
2025-01-28 17:08
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23142", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:36:51.042238Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:48:11.351Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.470Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:08:45.751Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23142", "datePublished": "2024-06-25T01:24:02.359Z", "dateReserved": "2024-01-11T21:51:08.013Z", "dateUpdated": "2025-01-28T17:08:45.751Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23130 (GCVE-0-2024-23130)
Vulnerability from cvelistv5
Published
2024-02-22 03:33
Modified
2025-01-28 16:43
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23130", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:25:46.144Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.563Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:43:57.493Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23130", "datePublished": "2024-02-22T03:33:55.872Z", "dateReserved": "2024-01-11T21:47:40.855Z", "dateUpdated": "2025-01-28T16:43:57.493Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-25791 (GCVE-0-2022-25791)
Vulnerability from cvelistv5
Published
2022-04-11 19:37
Modified
2024-08-03 04:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Memory Corruption
Summary
A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T04:49:43.624Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files." } ], "problemTypes": [ { "descriptions": [ { "description": "Memory Corruption ", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-11T19:37:51", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-25791", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Memory Corruption " } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-25791", "datePublished": "2022-04-11T19:37:51", "dateReserved": "2022-02-22T00:00:00", "dateUpdated": "2024-08-03T04:49:43.624Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23157 (GCVE-0-2024-23157)
Vulnerability from cvelistv5
Published
2024-06-25 03:30
Modified
2025-01-28 17:43
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23157", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-27T20:33:31.339206Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-27T20:33:37.827Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.791Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:43:23.440Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23157", "datePublished": "2024-06-25T03:30:58.799Z", "dateReserved": "2024-01-11T21:51:41.601Z", "dateUpdated": "2025-01-28T17:43:23.440Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37005 (GCVE-0-2024-37005)
Vulnerability from cvelistv5
Published
2024-06-25 03:13
Modified
2025-01-28 17:11
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37005", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:24:16.255743Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:24:21.346Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.683Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:11:33.127Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37005", "datePublished": "2024-06-25T03:13:51.990Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:11:33.127Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23151 (GCVE-0-2024-23151)
Vulnerability from cvelistv5
Published
2024-06-25 03:24
Modified
2025-02-10 20:56
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23151", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-26T19:49:38.703918Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-10T14:26:05.520Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.713Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T20:56:29.024Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23151", "datePublished": "2024-06-25T03:24:54.043Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-02-10T20:56:29.024Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-5047 (GCVE-0-2025-5047)
Vulnerability from cvelistv5
Published
2025-08-15 14:37
Modified
2025-08-19 13:20
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2026 < 2026.1 cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:* |
||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-5047", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-08-15T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-08-16T03:55:52.738Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:20:13.332Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017" } ], "source": { "discovery": "EXTERNAL" }, "title": "DGN File Parsing Uninitialized Variable Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-5047", "datePublished": "2025-08-15T14:37:49.550Z", "dateReserved": "2025-05-21T13:01:06.314Z", "dateUpdated": "2025-08-19T13:20:13.332Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23143 (GCVE-0-2024-23143)
Vulnerability from cvelistv5
Published
2024-06-25 02:05
Modified
2025-01-28 17:09
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23143", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:32:09.443136Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:32:13.678Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.730Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:09:19.775Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23143", "datePublished": "2024-06-25T02:05:33.461Z", "dateReserved": "2024-01-11T21:51:08.013Z", "dateUpdated": "2025-01-28T17:09:19.775Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-36999 (GCVE-0-2024-36999)
Vulnerability from cvelistv5
Published
2024-06-25 03:33
Modified
2025-02-10 20:53
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2024.1.5:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-36999", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-26T19:11:39.790482Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-26T19:18:29.026Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.596Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T20:53:40.826Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-36999", "datePublished": "2024-06-25T03:33:58.183Z", "dateReserved": "2024-05-30T20:11:46.548Z", "dateUpdated": "2025-02-10T20:53:40.826Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23148 (GCVE-0-2024-23148)
Vulnerability from cvelistv5
Published
2024-06-25 02:42
Modified
2025-01-27 21:42
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23148", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:28:48.562977Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:28:53.912Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:32.154Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-27T21:42:43.484Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23148", "datePublished": "2024-06-25T02:42:11.300Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-01-27T21:42:43.484Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23121 (GCVE-0-2024-23121)
Vulnerability from cvelistv5
Published
2024-02-22 01:18
Modified
2025-02-10 21:06
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23121", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:39:38.054542Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:44:37.274Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.662Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:06:41.131Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23121", "datePublished": "2024-02-22T01:18:23.487Z", "dateReserved": "2024-01-11T21:46:45.745Z", "dateUpdated": "2025-02-10T21:06:41.131Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-40161 (GCVE-0-2021-40161)
Vulnerability from cvelistv5
Published
2021-12-23 18:31
Modified
2024-08-04 02:27
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Memory Corruption Vulnerability
Summary
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T02:27:31.589Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Revit, Navisworks, Autodesk\u00ae Advance Steel, AutoCAD\u00ae, AutoCAD\u00ae Architecture, AutoCAD\u00ae Electrical, AutoCAD\u00ae Map 3D, AutoCAD\u00ae Mechanical, AutoCAD\u00ae MEP, AutoCAD\u00ae Plant 3D, AutoCAD\u00ae LT, Autodesk\u00ae Civil 3D, AutoCAD\u00ae Mac, AutoCAD\u00ae LT for Mac", "vendor": "n/a", "versions": [ { "status": "affected", "version": "prior to 9.0.7" } ] } ], "descriptions": [ { "lang": "en", "value": "A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version." } ], "problemTypes": [ { "descriptions": [ { "description": "Memory Corruption Vulnerability", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-18T16:20:49", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2021-40161", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Revit, Navisworks, Autodesk\u00ae Advance Steel, AutoCAD\u00ae, AutoCAD\u00ae Architecture, AutoCAD\u00ae Electrical, AutoCAD\u00ae Map 3D, AutoCAD\u00ae Mechanical, AutoCAD\u00ae MEP, AutoCAD\u00ae Plant 3D, AutoCAD\u00ae LT, Autodesk\u00ae Civil 3D, AutoCAD\u00ae Mac, AutoCAD\u00ae LT for Mac", "version": { "version_data": [ { "version_value": "prior to 9.0.7" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Memory Corruption Vulnerability" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-40161", "datePublished": "2021-12-23T18:31:43", "dateReserved": "2021-08-27T00:00:00", "dateUpdated": "2024-08-04T02:27:31.589Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23153 (GCVE-0-2024-23153)
Vulnerability from cvelistv5
Published
2024-06-25 03:26
Modified
2025-01-28 17:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23153", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-27T20:33:01.431935Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-27T20:33:10.949Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.684Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:46:20.874Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23153", "datePublished": "2024-06-25T03:26:37.392Z", "dateReserved": "2024-01-11T21:51:21.128Z", "dateUpdated": "2025-01-28T17:46:20.874Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1429 (GCVE-0-2025-1429)
Vulnerability from cvelistv5
Published
2025-03-13 16:47
Modified
2025-08-19 12:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-Based Buffer Overflow
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1429", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:40.927Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-Based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:49:52.296Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "MODEL File Parsing Heap-Based Buffer Overflow Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1429", "datePublished": "2025-03-13T16:47:42.309Z", "dateReserved": "2025-02-18T14:22:13.685Z", "dateUpdated": "2025-08-19T12:49:52.296Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23123 (GCVE-0-2024-23123)
Vulnerability from cvelistv5
Published
2024-02-22 01:38
Modified
2025-02-10 21:04
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23123", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:47:52.543Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.726Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:04:15.767Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23123", "datePublished": "2024-02-22T01:38:25.066Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-02-10T21:04:15.767Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2019-7361 (GCVE-0-2019-7361)
Vulnerability from cvelistv5
Published
2019-04-09 19:22
Modified
2024-08-04 20:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Deserialization of Untrusted Data
Summary
An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | Autodesk Civil 3D |
Version: 2018 |
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T20:46:46.387Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Civil 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk Advance Steel", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Map 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD P\u0026ID", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD LT", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] } ], "descriptions": [ { "lang": "en", "value": "An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018." } ], "problemTypes": [ { "descriptions": [ { "description": "Deserialization of Untrusted Data", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2019-04-09T19:22:15", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2019-7361", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Civil 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk Advance Steel", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Architecture", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Electrical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Map 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Mechanical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD MEP", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD P\u0026ID", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD LT", "version": { "version_data": [ { "version_value": "2018" } ] } } ] }, "vendor_name": "Autodesk" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Deserialization of Untrusted Data" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2019-7361", "datePublished": "2019-04-09T19:22:15", "dateReserved": "2019-02-04T00:00:00", "dateUpdated": "2024-08-04T20:46:46.387Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23120 (GCVE-0-2024-23120)
Vulnerability from cvelistv5
Published
2024-02-21 23:36
Modified
2025-02-10 21:07
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23120", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-07-26T16:45:26.511301Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:45:51.357Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.563Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:07:50.709Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23120", "datePublished": "2024-02-21T23:36:13.617Z", "dateReserved": "2024-01-11T21:46:45.745Z", "dateUpdated": "2025-02-10T21:07:50.709Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23133 (GCVE-0-2024-23133)
Vulnerability from cvelistv5
Published
2024-02-22 04:11
Modified
2025-01-27 18:01
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23133", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:27:51.295Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.217Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-27T18:01:20.631Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23133", "datePublished": "2024-02-22T04:11:47.319Z", "dateReserved": "2024-01-11T21:47:40.856Z", "dateUpdated": "2025-01-27T18:01:20.631Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37007 (GCVE-0-2024-37007)
Vulnerability from cvelistv5
Published
2024-06-25 03:35
Modified
2025-01-28 17:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37007", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-26T18:59:23.695414Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-26T19:12:43.909Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.671Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:49:14.941Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37007", "datePublished": "2024-06-25T03:35:23.524Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:49:14.941Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-25792 (GCVE-0-2022-25792)
Vulnerability from cvelistv5
Published
2022-04-11 19:37
Modified
2024-08-03 04:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Buffer Overflow
Summary
A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T04:49:43.219Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Buffer Overflow", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-11T19:37:52", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-25792", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Buffer Overflow" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-25792", "datePublished": "2022-04-11T19:37:52", "dateReserved": "2022-02-22T00:00:00", "dateUpdated": "2024-08-03T04:49:43.219Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-27529 (GCVE-0-2022-27529)
Vulnerability from cvelistv5
Published
2022-04-18 16:20
Modified
2024-08-03 05:32
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bounds Write
Summary
A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022, 2021, 2020, 2019 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T05:32:58.676Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022, 2021, 2020, 2019" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bounds Write", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-18T16:20:27", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-27529", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022, 2021, 2020, 2019" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Out-of-bounds Write" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-27529", "datePublished": "2022-04-18T16:20:27", "dateReserved": "2022-03-21T00:00:00", "dateUpdated": "2024-08-03T05:32:58.676Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23128 (GCVE-0-2024-23128)
Vulnerability from cvelistv5
Published
2024-02-22 03:18
Modified
2025-01-28 16:20
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23128", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:27:14.348745Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:26:50.336Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.695Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:20:38.429Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23128", "datePublished": "2024-02-22T03:18:00.232Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-01-28T16:20:38.429Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1432 (GCVE-0-2025-1432)
Vulnerability from cvelistv5
Published
2025-03-13 16:49
Modified
2025-08-19 15:06
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1432", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:36.579Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T15:06:22.414Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "3DM File Parsing Use-After-Free Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1432", "datePublished": "2025-03-13T16:49:14.298Z", "dateReserved": "2025-02-18T14:22:16.656Z", "dateUpdated": "2025-08-19T15:06:22.414Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-40160 (GCVE-0-2021-40160)
Vulnerability from cvelistv5
Published
2021-12-23 18:31
Modified
2024-08-04 02:27
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bound Read Vulnerability
Summary
PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T02:27:31.871Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Revit, Navisworks, Autodesk\u00ae Advance Steel, AutoCAD\u00ae, AutoCAD\u00ae Architecture, AutoCAD\u00ae Electrical, AutoCAD\u00ae Map 3D, AutoCAD\u00ae Mechanical, AutoCAD\u00ae MEP, AutoCAD\u00ae Plant 3D, AutoCAD\u00ae LT, Autodesk\u00ae Civil 3D, AutoCAD\u00ae Mac, AutoCAD\u00ae LT for Mac", "vendor": "n/a", "versions": [ { "status": "affected", "version": "prior to 9.0.7" } ] } ], "descriptions": [ { "lang": "en", "value": "PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bound Read Vulnerability", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-18T16:20:48", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2021-40160", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Revit, Navisworks, Autodesk\u00ae Advance Steel, AutoCAD\u00ae, AutoCAD\u00ae Architecture, AutoCAD\u00ae Electrical, AutoCAD\u00ae Map 3D, AutoCAD\u00ae Mechanical, AutoCAD\u00ae MEP, AutoCAD\u00ae Plant 3D, AutoCAD\u00ae LT, Autodesk\u00ae Civil 3D, AutoCAD\u00ae Mac, AutoCAD\u00ae LT for Mac", "version": { "version_data": [ { "version_value": "prior to 9.0.7" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Out-of-bound Read Vulnerability" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-40160", "datePublished": "2021-12-23T18:31:31", "dateReserved": "2021-08-27T00:00:00", "dateUpdated": "2024-08-04T02:27:31.871Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-6637 (GCVE-0-2025-6637)
Vulnerability from cvelistv5
Published
2025-07-29 17:56
Modified
2025-08-19 13:22
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-Bounds Write
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-6637", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:55.467Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-Bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:22:28.965Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "PRT File Parsing Out-of-Bounds Write Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-6637", "datePublished": "2025-07-29T17:56:50.031Z", "dateReserved": "2025-06-25T13:44:28.817Z", "dateUpdated": "2025-08-19T13:22:28.965Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23124 (GCVE-0-2024-23124)
Vulnerability from cvelistv5
Published
2024-02-22 02:14
Modified
2025-02-10 21:10
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23124", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:48:26.955Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.697Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:10:20.225Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23124", "datePublished": "2024-02-22T02:14:25.627Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-02-10T21:10:20.225Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-25789 (GCVE-0-2022-25789)
Vulnerability from cvelistv5
Published
2022-04-11 19:37
Modified
2024-08-03 04:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Use-after-free
Summary
A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T04:49:43.569Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution." } ], "problemTypes": [ { "descriptions": [ { "description": "Use-after-free", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-11T19:37:50", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-25789", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Use-after-free" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-25789", "datePublished": "2022-04-11T19:37:50", "dateReserved": "2022-02-22T00:00:00", "dateUpdated": "2024-08-03T04:49:43.569Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-25788 (GCVE-0-2022-25788)
Vulnerability from cvelistv5
Published
2022-04-19 20:26
Modified
2024-08-03 04:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bound Write
Summary
A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T04:49:43.514Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bound Write", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-19T20:26:31", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-25788", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Out-of-bound Write" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-25788", "datePublished": "2022-04-19T20:26:31", "dateReserved": "2022-02-22T00:00:00", "dateUpdated": "2024-08-03T04:49:43.514Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2019-7359 (GCVE-0-2019-7359)
Vulnerability from cvelistv5
Published
2019-04-09 19:22
Modified
2024-08-04 20:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Use After Free
Summary
An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file with too many cell margins populating an AcCellMargin object may cause a heap overflow, resulting in code execution.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | Autodesk Advance Steel |
Version: 2018 |
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T20:46:46.278Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advance Steel", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Map 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD P\u0026ID", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD LT", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk Civil 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] } ], "descriptions": [ { "lang": "en", "value": "An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file with too many cell margins populating an AcCellMargin object may cause a heap overflow, resulting in code execution." } ], "problemTypes": [ { "descriptions": [ { "description": "Use After Free", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2019-05-13T16:26:16", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2019-7359", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advance Steel", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Architecture", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Electrical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Map 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Mechanical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD MEP", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD P\u0026ID", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD LT", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk Civil 3D", "version": { "version_data": [ { "version_value": "2018" } ] } } ] }, "vendor_name": "Autodesk" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file with too many cell margins populating an AcCellMargin object may cause a heap overflow, resulting in code execution." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Use After Free" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2019-7359", "datePublished": "2019-04-09T19:22:56", "dateReserved": "2019-02-04T00:00:00", "dateUpdated": "2024-08-04T20:46:46.278Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23122 (GCVE-0-2024-23122)
Vulnerability from cvelistv5
Published
2024-02-22 01:36
Modified
2025-02-10 21:05
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23122", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:39:23.052424Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:50:31.610Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.749Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "defaultStatus": "unaffected", "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:05:24.234Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23122", "datePublished": "2024-02-22T01:36:34.080Z", "dateReserved": "2024-01-11T21:46:45.745Z", "dateUpdated": "2025-02-10T21:05:24.234Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-5048 (GCVE-0-2025-5048)
Vulnerability from cvelistv5
Published
2025-08-15 14:38
Modified
2025-08-19 13:20
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Summary
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2026 < 2026.1 cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:* |
||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-5048", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-08-15T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-08-16T03:55:55.060Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-120", "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:20:29.119Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017" } ], "source": { "discovery": "EXTERNAL" }, "title": "DGN File Parsing Memory Corruption Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-5048", "datePublished": "2025-08-15T14:38:22.151Z", "dateReserved": "2025-05-21T13:01:07.347Z", "dateUpdated": "2025-08-19T13:20:29.119Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23125 (GCVE-0-2024-23125)
Vulnerability from cvelistv5
Published
2024-02-22 02:23
Modified
2025-01-30 18:35
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-121 - Stack-based Buffer Overflow
Summary
A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23125", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:49:02.446Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.719Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-121", "description": "CWE-121: Stack-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-30T18:35:55.550Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23125", "datePublished": "2024-02-22T02:23:09.032Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-01-30T18:35:55.550Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23135 (GCVE-0-2024-23135)
Vulnerability from cvelistv5
Published
2024-02-22 04:34
Modified
2025-01-27 18:00
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23135", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:23:06.907Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.696Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-27T18:00:30.254Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23135", "datePublished": "2024-02-22T04:34:27.533Z", "dateReserved": "2024-01-11T21:47:40.857Z", "dateUpdated": "2025-01-27T18:00:30.254Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1428 (GCVE-0-2025-1428)
Vulnerability from cvelistv5
Published
2025-03-13 16:46
Modified
2025-08-19 12:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-Bounds Read
Summary
A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1428", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:24.607Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-Bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:49:25.168Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "CATPRODUCT File Parsing Out-of-Bounds Read Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1428", "datePublished": "2025-03-13T16:46:22.348Z", "dateReserved": "2025-02-18T14:22:12.740Z", "dateUpdated": "2025-08-19T12:49:25.168Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37006 (GCVE-0-2024-37006)
Vulnerability from cvelistv5
Published
2024-06-25 03:15
Modified
2025-01-28 16:15
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37006", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:16:33.319239Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T21:04:07.767Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.517Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:15:50.637Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37006", "datePublished": "2024-06-25T03:15:46.957Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T16:15:50.637Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23134 (GCVE-0-2024-23134)
Vulnerability from cvelistv5
Published
2024-02-22 04:27
Modified
2025-01-28 16:59
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23134", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:44:12.044Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.292Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4**", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4**", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:59:21.137Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23134", "datePublished": "2024-02-22T04:27:15.155Z", "dateReserved": "2024-01-11T21:47:40.856Z", "dateUpdated": "2025-01-28T16:59:21.137Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-40159 (GCVE-0-2021-40159)
Vulnerability from cvelistv5
Published
2022-01-25 00:00
Modified
2024-08-04 02:27
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Information Disclosure
Summary
An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T02:27:31.832Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-282/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-289/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Inventor", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022, 2021, 2020, 2019" } ] } ], "descriptions": [ { "lang": "en", "value": "An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process." } ], "problemTypes": [ { "descriptions": [ { "description": "Information Disclosure", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-10-07T00:00:00", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-282/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-289/" } ] } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-40159", "datePublished": "2022-01-25T00:00:00", "dateReserved": "2021-08-27T00:00:00", "dateUpdated": "2024-08-04T02:27:31.832Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-40158 (GCVE-0-2021-40158)
Vulnerability from cvelistv5
Published
2022-01-25 00:00
Modified
2024-08-04 02:27
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bounds Read
Summary
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
► | URL | Tags | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T02:27:31.854Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-287/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-283/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-288/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-286/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-284/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-285/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-281/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-449/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-441/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-453/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-444/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-447/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-448/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-452/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-445/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-466/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-451/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-454/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-443/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-450/" }, { "tags": [ "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-455/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Inventor", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022, 2021, 2020, 2019" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bounds Read", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-10-07T00:00:00", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-287/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-283/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-288/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-286/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-284/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-285/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-281/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-449/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-441/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-453/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-444/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-447/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-448/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-452/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-445/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-466/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-451/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-454/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-443/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-450/" }, { "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-455/" } ] } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-40158", "datePublished": "2022-01-25T00:00:00", "dateReserved": "2021-08-27T00:00:00", "dateUpdated": "2024-08-04T02:27:31.854Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23154 (GCVE-0-2024-23154)
Vulnerability from cvelistv5
Published
2024-06-25 03:27
Modified
2025-01-28 17:45
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-based Buffer Overflow
Summary
A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2013:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThanOrEqual": "2024", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 6.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23154", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T14:39:05.594512Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T15:05:55.662Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.739Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:45:43.752Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23154", "datePublished": "2024-06-25T03:27:56.293Z", "dateReserved": "2024-01-11T21:51:21.128Z", "dateUpdated": "2025-01-28T17:45:43.752Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1433 (GCVE-0-2025-1433)
Vulnerability from cvelistv5
Published
2025-03-13 16:51
Modified
2025-08-19 12:56
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-Bounds Read
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1433", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-03-13T19:36:31.756658Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-03-13T19:36:44.047Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-Bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:56:16.723Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "MODEL File Parsing Out-of-Bounds Read Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1433", "datePublished": "2025-03-13T16:51:06.105Z", "dateReserved": "2025-02-18T14:22:17.563Z", "dateUpdated": "2025-08-19T12:56:16.723Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23150 (GCVE-0-2024-23150)
Vulnerability from cvelistv5
Published
2024-06-25 03:17
Modified
2025-02-10 20:55
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23150", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-27T20:31:33.417050Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-27T20:32:16.056Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.805Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T20:55:21.598Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23150", "datePublished": "2024-06-25T03:17:21.321Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-02-10T20:55:21.598Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37002 (GCVE-0-2024-37002)
Vulnerability from cvelistv5
Published
2024-06-25 03:07
Modified
2025-01-28 17:13
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37002", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:12:54.230669Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-863", "description": "CWE-863 Incorrect Authorization", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:34:16.515Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.523Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:13:47.607Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37002", "datePublished": "2024-06-25T03:07:28.673Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:13:47.607Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-5038 (GCVE-0-2025-5038)
Vulnerability from cvelistv5
Published
2025-07-29 17:51
Modified
2025-08-19 13:17
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Summary
A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-5038", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:49.666Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-120", "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:17:02.999Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "X_T File Parsing Memory Corruption Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-5038", "datePublished": "2025-07-29T17:51:59.877Z", "dateReserved": "2025-05-21T13:00:58.307Z", "dateUpdated": "2025-08-19T13:17:02.999Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23132 (GCVE-0-2024-23132)
Vulnerability from cvelistv5
Published
2024-02-22 04:10
Modified
2025-01-27 18:02
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23132", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:24:43.526Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.681Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-27T18:02:14.838Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23132", "datePublished": "2024-02-22T04:10:53.175Z", "dateReserved": "2024-01-11T21:47:40.856Z", "dateUpdated": "2025-01-27T18:02:14.838Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-7497 (GCVE-0-2025-7497)
Vulnerability from cvelistv5
Published
2025-07-29 17:57
Modified
2025-08-19 13:22
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-Bounds Write
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-7497", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:56.262Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-Bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:22:46.904Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "PRT File Parsing Out-of-Bounds Write Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-7497", "datePublished": "2025-07-29T17:57:13.572Z", "dateReserved": "2025-07-11T15:02:31.021Z", "dateUpdated": "2025-08-19T13:22:46.904Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-5046 (GCVE-0-2025-5046)
Vulnerability from cvelistv5
Published
2025-08-15 14:37
Modified
2025-08-19 13:19
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-Bounds Read
Summary
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2026 < 2026.1 cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:* |
||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-5046", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-08-15T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-08-16T03:55:53.889Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.1", "status": "affected", "version": "2026", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-Bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:19:54.615Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017" } ], "source": { "discovery": "EXTERNAL" }, "title": "DGN File Parsing Out-of-Bounds Read Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-5046", "datePublished": "2025-08-15T14:37:20.897Z", "dateReserved": "2025-05-21T13:01:05.437Z", "dateUpdated": "2025-08-19T13:19:54.615Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37000 (GCVE-0-2024-37000)
Vulnerability from cvelistv5
Published
2024-06-25 03:01
Modified
2025-01-28 17:16
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37000", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:23:33.352025Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:23:40.959Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.657Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:16:03.323Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37000", "datePublished": "2024-06-25T03:01:53.604Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:16:03.323Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1649 (GCVE-0-2025-1649)
Vulnerability from cvelistv5
Published
2025-03-13 16:51
Modified
2025-08-19 13:11
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1649", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:35.259Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:11:40.994Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "CATPRODUCT File Parsing Uninitialized Variable Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1649", "datePublished": "2025-03-13T16:51:13.073Z", "dateReserved": "2025-02-24T19:20:20.631Z", "dateUpdated": "2025-08-19T13:11:40.994Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-6635 (GCVE-0-2025-6635)
Vulnerability from cvelistv5
Published
2025-07-29 17:53
Modified
2025-08-19 13:21
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-Bounds Read
Summary
A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-6635", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:52.940Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-Bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:21:59.522Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "PRT File Parsing Out-of-Bounds Read Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-6635", "datePublished": "2025-07-29T17:53:35.895Z", "dateReserved": "2025-06-25T13:44:26.482Z", "dateUpdated": "2025-08-19T13:21:59.522Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23138 (GCVE-0-2024-23138)
Vulnerability from cvelistv5
Published
2024-03-17 23:56
Modified
2025-01-28 18:31
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-121 - Stack-based Buffer Overflow
Summary
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.676Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0006" } ], "title": "CVE Program Container" }, { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23138", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-04-12T04:00:27.602332Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-08-05T13:43:04.862Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:aautocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mac:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mac:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mac:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mac", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.4.1", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_lt_for_mac:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt_for_mac:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt_for_mac:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT for Mac", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.4.1", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "DWG TrueView", "vendor": "Autodesk", "versions": [ { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-121", "description": "CWE-121: Stack-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T18:31:08.067Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0006" } ], "source": { "discovery": "EXTERNAL" }, "title": "Stack-based Overflow Vulnerability in the TrueViewTM Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23138", "datePublished": "2024-03-17T23:56:39.590Z", "dateReserved": "2024-01-11T21:47:40.857Z", "dateUpdated": "2025-01-28T18:31:08.067Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-5043 (GCVE-0-2025-5043)
Vulnerability from cvelistv5
Published
2025-07-29 17:52
Modified
2025-08-19 13:19
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-Based Buffer Overflow
Summary
A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-5043", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:50.498Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-Based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:19:36.659Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "3DM File Parsing Heap-Based Overflow Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-5043", "datePublished": "2025-07-29T17:52:37.857Z", "dateReserved": "2025-05-21T13:01:02.814Z", "dateUpdated": "2025-08-19T13:19:36.659Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23159 (GCVE-0-2024-23159)
Vulnerability from cvelistv5
Published
2024-06-25 03:33
Modified
2025-01-28 17:22
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23159", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-27T20:33:57.567211Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-27T20:34:05.942Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.524Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:22:00.922Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23159", "datePublished": "2024-06-25T03:33:00.849Z", "dateReserved": "2024-01-11T21:51:41.602Z", "dateUpdated": "2025-01-28T17:22:00.922Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23127 (GCVE-0-2024-23127)
Vulnerability from cvelistv5
Published
2024-02-22 02:59
Modified
2025-01-28 16:41
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-based Buffer Overflow
Summary
A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23127", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:27:13.556Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.212Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122: Heap-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:41:31.146Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23127", "datePublished": "2024-02-22T02:59:48.198Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-01-28T16:41:31.146Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2019-7358 (GCVE-0-2019-7358)
Vulnerability from cvelistv5
Published
2019-04-09 19:22
Modified
2024-08-04 20:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Heap Overflow
Summary
An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may cause a heap overflow, resulting in code execution.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | Autodesk AutoCAD LT |
Version: 2018 |
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T20:46:46.191Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk AutoCAD LT", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk Civil 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk Advance Steel", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Map 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD P\u0026ID", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] } ], "descriptions": [ { "lang": "en", "value": "An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may cause a heap overflow, resulting in code execution." } ], "problemTypes": [ { "descriptions": [ { "description": "Heap Overflow", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2019-04-09T19:22:39", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2019-7358", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk AutoCAD LT", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk Civil 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk Advance Steel", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Architecture", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Electrical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Map 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Mechanical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD MEP", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD P\u0026ID", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2018" } ] } } ] }, "vendor_name": "Autodesk" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may cause a heap overflow, resulting in code execution." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Heap Overflow" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2019-7358", "datePublished": "2019-04-09T19:22:39", "dateReserved": "2019-02-04T00:00:00", "dateUpdated": "2024-08-04T20:46:46.191Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23156 (GCVE-0-2024-23156)
Vulnerability from cvelistv5
Published
2024-06-25 03:30
Modified
2025-01-28 17:44
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:-:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:-:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23156", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-26T19:14:44.418256Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-26T19:17:50.940Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:32.153Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:44:43.777Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23156", "datePublished": "2024-06-25T03:30:03.304Z", "dateReserved": "2024-01-11T21:51:41.601Z", "dateUpdated": "2025-01-28T17:44:43.777Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1276 (GCVE-0-2025-1276)
Vulnerability from cvelistv5
Published
2025-04-15 20:55
Modified
2025-08-19 12:48
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-Bounds Write
Summary
A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:* |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1276", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-17T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-18T03:55:45.569Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:realdwg:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:realdwg:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "RealDWG", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:dwg_trueview:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "DWG TrueView", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-Bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:48:17.475Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/dwg-trueview/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "DWG File Parsing Out-of-Bounds Write Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1276", "datePublished": "2025-04-15T20:55:04.255Z", "dateReserved": "2025-02-13T15:16:31.469Z", "dateUpdated": "2025-08-19T12:48:17.475Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-27042 (GCVE-0-2021-27042)
Vulnerability from cvelistv5
Published
2021-06-25 12:41
Modified
2024-08-03 20:40
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Memory Corruption Vulnerability
Summary
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T20:40:47.367Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Memory Corruption Vulnerability ", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-13T17:06:06", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2021-27042", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Memory Corruption Vulnerability " } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-27042", "datePublished": "2021-06-25T12:41:19", "dateReserved": "2021-02-09T00:00:00", "dateUpdated": "2024-08-03T20:40:47.367Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23145 (GCVE-0-2024-23145)
Vulnerability from cvelistv5
Published
2024-06-25 02:27
Modified
2025-01-28 17:10
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23145", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:30:24.476007Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:30:33.823Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.212Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:10:41.064Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23145", "datePublished": "2024-06-25T02:27:23.995Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-01-28T17:10:41.064Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23158 (GCVE-0-2024-23158)
Vulnerability from cvelistv5
Published
2024-06-25 03:31
Modified
2025-01-28 17:42
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.2, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23158", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T14:31:23.903824Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T14:31:27.866Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.445Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:42:36.507Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23158", "datePublished": "2024-06-25T03:31:47.315Z", "dateReserved": "2024-01-11T21:51:41.602Z", "dateUpdated": "2025-01-28T17:42:36.507Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23136 (GCVE-0-2024-23136)
Vulnerability from cvelistv5
Published
2024-02-22 04:48
Modified
2025-02-03 15:44
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-822 - Untrusted Pointer Dereference
Summary
A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23136", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:23:25.405Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.674Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-129", "descriptions": [ { "lang": "en", "value": "CAPEC-129 Pointer Manipulation" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-822", "description": "CWE-822: Untrusted Pointer Dereference", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-03T15:44:07.671Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23136", "datePublished": "2024-02-22T04:48:25.677Z", "dateReserved": "2024-01-11T21:47:40.857Z", "dateUpdated": "2025-02-03T15:44:07.671Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1427 (GCVE-0-2025-1427)
Vulnerability from cvelistv5
Published
2025-03-13 16:46
Modified
2025-08-19 12:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1427", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:23.262Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:49:03.122Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "CATPRODUCT File Parsing Uninitialized Variable Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1427", "datePublished": "2025-03-13T16:46:05.612Z", "dateReserved": "2025-02-18T14:22:11.431Z", "dateUpdated": "2025-08-19T12:49:03.122Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-0446 (GCVE-0-2024-0446)
Vulnerability from cvelistv5
Published
2024-02-21 23:16
Modified
2025-02-10 21:11
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-0446", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T18:06:35.579754Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:46:59.046Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T18:04:49.768Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:11:14.382Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-0446", "datePublished": "2024-02-21T23:16:32.477Z", "dateReserved": "2024-01-11T21:51:23.386Z", "dateUpdated": "2025-02-10T21:11:14.382Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1650 (GCVE-0-2025-1650)
Vulnerability from cvelistv5
Published
2025-03-13 16:51
Modified
2025-08-19 13:12
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1650", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:33.960Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:12:00.933Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "CATPRODUCT File Parsing Uninitialized Variable Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1650", "datePublished": "2025-03-13T16:51:22.108Z", "dateReserved": "2025-02-24T19:20:21.610Z", "dateUpdated": "2025-08-19T13:12:00.933Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23144 (GCVE-0-2024-23144)
Vulnerability from cvelistv5
Published
2024-06-25 02:10
Modified
2025-02-10 21:00
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23144", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:31:17.885600Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:31:22.080Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.414Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:00:57.694Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23144", "datePublished": "2024-06-25T02:10:02.389Z", "dateReserved": "2024-01-11T21:51:08.013Z", "dateUpdated": "2025-02-10T21:00:57.694Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1431 (GCVE-0-2025-1431)
Vulnerability from cvelistv5
Published
2025-03-13 16:48
Modified
2025-08-19 12:50
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-Bounds Read
Summary
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1431", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:38.051Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-Bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:50:43.475Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "SLDPRT File Parsing Out-of-Bounds Read Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1431", "datePublished": "2025-03-13T16:48:51.554Z", "dateReserved": "2025-02-18T14:22:15.667Z", "dateUpdated": "2025-08-19T12:50:43.475Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2019-7364 (GCVE-0-2019-7364)
Vulnerability from cvelistv5
Published
2019-08-23 19:36
Modified
2024-08-04 20:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- DLL preloading vulnerability
Summary
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, AutoCAD P&ID |
Version: 2017, 2018, 2019, 2020 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T20:46:46.182Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, AutoCAD P\u0026ID", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2017, 2018, 2019, 2020" } ] } ], "descriptions": [ { "lang": "en", "value": "DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P\u0026ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution." } ], "problemTypes": [ { "descriptions": [ { "description": "DLL preloading vulnerability", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2019-08-23T19:36:17", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2019-7364", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, AutoCAD P\u0026ID", "version": { "version_data": [ { "version_value": "2017, 2018, 2019, 2020" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P\u0026ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "DLL preloading vulnerability" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002", "refsource": "CONFIRM", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2019-7364", "datePublished": "2019-08-23T19:36:17", "dateReserved": "2019-02-04T00:00:00", "dateUpdated": "2024-08-04T20:46:46.182Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23146 (GCVE-0-2024-23146)
Vulnerability from cvelistv5
Published
2024-06-25 02:28
Modified
2025-02-10 21:01
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23146", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:30:00.518542Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:30:06.364Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.702Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-10T21:01:58.711Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23146", "datePublished": "2024-06-25T02:28:20.607Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-02-10T21:01:58.711Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1275 (GCVE-0-2025-1275)
Vulnerability from cvelistv5
Published
2025-04-15 20:54
Modified
2025-08-19 12:47
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-Based Buffer Overflow
Summary
A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | Revit |
Version: 2025 < 2025.4.1 Version: 2024 < 2024.3.2 Version: 2023 < 2023.1.7 cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:* |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1275", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-17T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-18T03:55:30.759Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Revit", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.4.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.3.2", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:dwg_trueview:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "DWG TrueView", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-Based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:47:53.443Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/dwg-trueview/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0006" } ], "source": { "discovery": "EXTERNAL" }, "title": "JPG File Parsing Heap-Based Overflow Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1275", "datePublished": "2025-04-15T20:54:30.139Z", "dateReserved": "2025-02-13T15:16:30.397Z", "dateUpdated": "2025-08-19T12:47:53.443Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23140 (GCVE-0-2024-23140)
Vulnerability from cvelistv5
Published
2024-06-25 01:01
Modified
2025-01-28 17:02
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23140", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:57:54.776746Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:58:02.177Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.701Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:02:22.364Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23140", "datePublished": "2024-06-25T01:01:56.652Z", "dateReserved": "2024-01-11T21:51:08.013Z", "dateUpdated": "2025-01-28T17:02:22.364Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2019-7360 (GCVE-0-2019-7360)
Vulnerability from cvelistv5
Published
2019-04-09 19:21
Modified
2024-08-04 20:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Heap Overflow
Summary
An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | Autodesk Civil 3D |
Version: 2018 |
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T20:46:46.198Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Civil 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk Advance Steel", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Map 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD P\u0026ID", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] }, { "product": "Autodesk AutoCAD LT", "vendor": "Autodesk", "versions": [ { "status": "affected", "version": "2018" } ] } ], "descriptions": [ { "lang": "en", "value": "An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution." } ], "problemTypes": [ { "descriptions": [ { "description": "Heap Overflow", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2019-05-13T16:32:48", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2019-7360", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Civil 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk Advance Steel", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Architecture", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Electrical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Map 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Mechanical", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD MEP", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD P\u0026ID", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2018" } ] } }, { "product_name": "Autodesk AutoCAD LT", "version": { "version_data": [ { "version_value": "2018" } ] } } ] }, "vendor_name": "Autodesk" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Heap Overflow" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2019-7360", "datePublished": "2019-04-09T19:21:46", "dateReserved": "2019-02-04T00:00:00", "dateUpdated": "2024-08-04T20:46:46.198Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1430 (GCVE-0-2025-1430)
Vulnerability from cvelistv5
Published
2025-03-13 16:48
Modified
2025-08-19 12:50
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Summary
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1430", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:39.550Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-120", "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T12:50:16.708Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "SLDPRT File Parsing Memory Corruption Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1430", "datePublished": "2025-03-13T16:48:13.960Z", "dateReserved": "2025-02-18T14:22:14.667Z", "dateUpdated": "2025-08-19T12:50:16.708Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1651 (GCVE-0-2025-1651)
Vulnerability from cvelistv5
Published
2025-03-13 16:51
Modified
2025-08-19 13:12
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-Based Buffer Overflow
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1651", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:32.604Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-Based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:12:23.282Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "MODEL File Parsing Heap-Based Buffer Overflow Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1651", "datePublished": "2025-03-13T16:51:30.258Z", "dateReserved": "2025-02-24T19:20:22.743Z", "dateUpdated": "2025-08-19T13:12:23.282Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-1652 (GCVE-0-2025-1652)
Vulnerability from cvelistv5
Published
2025-03-13 16:51
Modified
2025-08-19 13:12
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-Bounds Read
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.2 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-1652", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-04-24T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-04-25T03:55:29.964Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.2", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-Bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:12:43.604Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "patch" ], "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "source": { "discovery": "EXTERNAL" }, "title": "MODEL File Parsing Out-of-Bounds Read Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-1652", "datePublished": "2025-03-13T16:51:36.291Z", "dateReserved": "2025-02-24T19:20:23.915Z", "dateUpdated": "2025-08-19T13:12:43.604Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-8587 (GCVE-0-2024-8587)
Vulnerability from cvelistv5
Published
2024-10-29 21:03
Modified
2025-04-25 20:08
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-based Buffer Overflow
Summary
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1.1 Version: 2024 < 2024.1.7 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2024-8587", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-10-30T13:51:55.963535Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-10-30T15:03:53.927Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.7", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process." } ], "value": "A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-04-25T20:08:26.047Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0019" } ], "source": { "discovery": "UNKNOWN" }, "title": "Autodesk AutoCAD SLDPRT File Parsing Heap-based Buffer Overflow Code Execution Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-8587", "datePublished": "2024-10-29T21:03:58.156Z", "dateReserved": "2024-09-09T03:01:59.536Z", "dateUpdated": "2025-04-25T20:08:26.047Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23155 (GCVE-0-2024-23155)
Vulnerability from cvelistv5
Published
2024-06-25 03:28
Modified
2025-01-28 17:45
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-based Buffer Overflow
Summary
A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23155", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-11-06T15:16:32.010596Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-11-06T15:18:20.717Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.298Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:45:12.363Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23155", "datePublished": "2024-06-25T03:28:44.767Z", "dateReserved": "2024-01-11T21:51:41.601Z", "dateUpdated": "2025-01-28T17:45:12.363Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-27043 (GCVE-0-2021-27043)
Vulnerability from cvelistv5
Published
2021-06-25 12:41
Modified
2024-08-03 20:40
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Write-what-where Condition Vulnerabiliity
Summary
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T20:40:47.163Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application." } ], "problemTypes": [ { "descriptions": [ { "description": "Write-what-where Condition Vulnerabiliity", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-13T17:06:07", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2021-27043", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Write-what-where Condition Vulnerabiliity" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-27043", "datePublished": "2021-06-25T12:41:26", "dateReserved": "2021-02-09T00:00:00", "dateUpdated": "2024-08-03T20:40:47.163Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23129 (GCVE-0-2024-23129)
Vulnerability from cvelistv5
Published
2024-02-22 03:24
Modified
2025-01-28 16:43
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23129", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:26:21.444Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.761Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:43:20.955Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23129", "datePublished": "2024-02-22T03:24:17.047Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-01-28T16:43:20.955Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-6636 (GCVE-0-2025-6636)
Vulnerability from cvelistv5
Published
2025-07-29 17:54
Modified
2025-08-19 13:22
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-6636", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:54.668Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:22:14.824Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "PRT File Parsing Use-After-Free Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-6636", "datePublished": "2025-07-29T17:54:02.053Z", "dateReserved": "2025-06-25T13:44:27.794Z", "dateUpdated": "2025-08-19T13:22:14.824Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23131 (GCVE-0-2024-23131)
Vulnerability from cvelistv5
Published
2024-02-22 04:05
Modified
2025-01-28 16:44
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23131", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:25:14.111Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.784Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:44:58.568Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23131", "datePublished": "2024-02-22T04:05:15.064Z", "dateReserved": "2024-01-11T21:47:40.856Z", "dateUpdated": "2025-01-28T16:44:58.568Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37004 (GCVE-0-2024-37004)
Vulnerability from cvelistv5
Published
2024-06-25 03:13
Modified
2025-01-28 17:12
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-416 - Use After Free
Summary
A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37004", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:24:45.484817Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:24:49.966Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.581Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:12:07.987Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37004", "datePublished": "2024-06-25T03:13:05.174Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:12:07.987Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23126 (GCVE-0-2024-23126)
Vulnerability from cvelistv5
Published
2024-02-22 02:25
Modified
2025-01-30 18:36
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-121 - Stack-based Buffer Overflow
Summary
A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23126", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-22T14:40:30.040434Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:49:30.533Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.572Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-121", "description": "CWE-121: Stack-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-30T18:36:29.533Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23126", "datePublished": "2024-02-22T02:25:01.889Z", "dateReserved": "2024-01-11T21:46:45.746Z", "dateUpdated": "2025-01-30T18:36:29.533Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23141 (GCVE-0-2024-23141)
Vulnerability from cvelistv5
Published
2024-06-25 01:22
Modified
2025-01-28 17:07
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-415 - Double Free
Summary
A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_map_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23141", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:49:27.556946Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:49:33.135Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.764Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-415", "description": "CWE-415 Double Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:07:41.834Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23141", "datePublished": "2024-06-25T01:22:38.407Z", "dateReserved": "2024-01-11T21:51:08.013Z", "dateUpdated": "2025-01-28T17:07:41.834Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23147 (GCVE-0-2024-23147)
Vulnerability from cvelistv5
Published
2024-06-25 02:32
Modified
2025-01-28 16:36
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-119 - Memory Corruption - Generic
Summary
A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23147", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:29:29.658321Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:29:34.487Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.741Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-119", "description": "CWE-119 Memory Corruption - Generic", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:36:26.055Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23147", "datePublished": "2024-06-25T02:32:13.779Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-01-28T16:36:26.055Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-37001 (GCVE-0-2024-37001)
Vulnerability from cvelistv5
Published
2024-06-25 03:03
Modified
2025-01-28 17:14
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-122 - Heap-based Buffer Overflow
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "advance_steel", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2024" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-37001", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:27:08.824776Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-06-25T13:27:16.818Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-02T03:43:50.467Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-122", "description": "CWE-122 Heap-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:14:26.439Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-37001", "datePublished": "2024-06-25T03:03:33.153Z", "dateReserved": "2024-05-30T20:11:46.549Z", "dateUpdated": "2025-01-28T17:14:26.439Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-6631 (GCVE-0-2025-6631)
Vulnerability from cvelistv5
Published
2025-07-29 17:53
Modified
2025-08-19 13:21
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-Bounds Write
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-6631", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:52.059Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-Bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:21:00.832Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "PRT File Parsing Out-of-Bounds Write Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-6631", "datePublished": "2025-07-29T17:53:04.135Z", "dateReserved": "2025-06-25T13:43:01.062Z", "dateUpdated": "2025-08-19T13:21:00.832Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-7305 (GCVE-0-2024-7305)
Vulnerability from cvelistv5
Published
2024-08-19 23:28
Modified
2025-04-25 21:04
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-bounds Write
Summary
A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.6 Version: 2023 < 2023.1.7 Version: 2022 < 2022.1.6 |
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mep", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_plant_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_architecture", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_electrical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_mechanical", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_lt", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:dwg_trueview:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "dwg_trueview", "vendor": "autodesk", "versions": [ { "status": "affected", "version": "2025" } ] } ], "metrics": [ { "other": { "content": { "id": "CVE-2024-7305", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-08-21T15:12:19.030297Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-08-21T15:25:35.299Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD LT", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:dwg_trueview:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "DWG TrueView", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:hotfix:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Map 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.6", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.7", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.6", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cp\u003eA maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/p\u003e" } ], "value": "A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-04-25T21:04:24.558Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0014" } ], "source": { "discovery": "UNKNOWN" }, "title": "DWF Vulnerability in Autodesk Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-7305", "datePublished": "2024-08-19T23:28:23.356Z", "dateReserved": "2024-07-30T19:31:26.704Z", "dateUpdated": "2025-04-25T21:04:24.558Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-27041 (GCVE-0-2021-27041)
Vulnerability from cvelistv5
Published
2021-06-25 12:41
Modified
2024-08-03 20:40
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bound Write Vulnerability
Summary
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T20:40:47.113Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code" } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bound Write Vulnerability", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-13T17:06:06", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2021-27041", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Out-of-bound Write Vulnerability" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-27041", "datePublished": "2021-06-25T12:41:13", "dateReserved": "2021-02-09T00:00:00", "dateUpdated": "2024-08-03T20:40:47.113Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2025-7675 (GCVE-0-2025-7675)
Vulnerability from cvelistv5
Published
2025-07-29 17:57
Modified
2025-08-19 13:23
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-787 - Out-of-Bounds Write
Summary
A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
► | URL | Tags |
---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Autodesk | Shared Components |
Version: 2026.2 < 2026.3 cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:* |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-7675", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-07-29T00:00:00+00:00", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-07-30T03:55:57.025Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Shared Components", "vendor": "Autodesk", "versions": [ { "lessThan": "2026.3", "status": "affected", "version": "2026.2", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-787", "description": "CWE-787 Out-of-Bounds Write", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-08-19T13:23:05.667Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "patch" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "tags": [ "vendor-advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "source": { "discovery": "EXTERNAL" }, "title": "3DM File Parsing Out-of-Bounds Write Vulnerability", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2025-7675", "datePublished": "2025-07-29T17:57:36.134Z", "dateReserved": "2025-07-15T12:31:56.589Z", "dateUpdated": "2025-08-19T13:23:05.667Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23137 (GCVE-0-2024-23137)
Vulnerability from cvelistv5
Published
2024-02-22 04:49
Modified
2025-01-28 17:00
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-457 - Use of Uninitialized Variable
Summary
A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.0.1 Version: 2024 < 2024.1.3 Version: 2023 < 2023.1.5 Version: 2022 < 2022.1.4 Version: 2021 < 2021.1.4 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "affected": [ { "cpes": [ "cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_advance_steel", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad_civil_3d", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] }, { "cpes": [ "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "autocad", "vendor": "autodesk", "versions": [ { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23137", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T14:01:49.435037Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2024-07-26T16:24:17.429Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:30.731Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] }, { "lessThan": "2021.1.4", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "version": "2021", "versionType": "custom", "versions": [ { "lessThan": "2025.0.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.3", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.5", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.4", "status": "affected", "version": "2022", "versionType": "custom" }, { "lessThan": "2021.1.4", "status": "affected", "version": "2021", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-457", "description": "CWE-457: Use of Uninitialized Variable", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:00:16.112Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23137", "datePublished": "2024-02-22T04:49:50.154Z", "dateReserved": "2024-01-11T21:47:40.857Z", "dateUpdated": "2025-01-28T17:00:16.112Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-25790 (GCVE-0-2022-25790)
Vulnerability from cvelistv5
Published
2022-04-11 19:37
Modified
2024-08-03 04:49
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bounds Write
Summary
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Navisworks, Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022.1, 2022.1.1 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T04:49:43.515Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Navisworks, Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022.1, 2022.1.1" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bounds Write", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-11T19:37:51", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-25790", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Navisworks, Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022.1, 2022.1.1" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Out-of-bounds Write" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-25790", "datePublished": "2022-04-11T19:37:51", "dateReserved": "2022-02-22T00:00:00", "dateUpdated": "2024-08-03T04:49:43.515Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23149 (GCVE-0-2024-23149)
Vulnerability from cvelistv5
Published
2024-06-25 02:43
Modified
2025-01-28 17:17
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.4 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.1, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23149", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-06-25T13:18:08.558926Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T16:36:03.136Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.673Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.4", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:17:05.420Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23149", "datePublished": "2024-06-25T02:43:08.569Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-01-28T17:17:05.420Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2024-23152 (GCVE-0-2024-23152)
Vulnerability from cvelistv5
Published
2024-06-25 03:25
Modified
2025-02-04 16:52
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-125 - Out-of-bounds Read
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | ||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | Autodesk | AutoCAD |
Version: 2025 < 2025.1 Version: 2024 < 2024.1.5 Version: 2023 < 2023.1.6 Version: 2022 < 2022.1.5 |
|||||||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 5.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2024-23152", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-02-04T16:51:34.502886Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-02-04T16:52:08.129Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" }, { "providerMetadata": { "dateUpdated": "2024-08-01T22:59:31.703Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "cpe": [ "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Architecture", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Electrical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Mechanical", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MEP", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD Plant 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Civil 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "Advance Steel", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] }, { "cpe": [ "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*", "cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:*" ], "defaultStatus": "unaffected", "product": "AutoCAD MAP 3D", "vendor": "Autodesk", "versions": [ { "lessThan": "2025.1", "status": "affected", "version": "2025", "versionType": "custom" }, { "lessThan": "2024.1.5", "status": "affected", "version": "2024", "versionType": "custom" }, { "lessThan": "2023.1.6", "status": "affected", "version": "2023", "versionType": "custom" }, { "lessThan": "2022.1.5", "status": "affected", "version": "2022", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e" } ], "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-01-28T17:47:13.846Z", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "source": { "discovery": "EXTERNAL" }, "title": "Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2024-23152", "datePublished": "2024-06-25T03:25:46.136Z", "dateReserved": "2024-01-11T21:51:21.127Z", "dateUpdated": "2025-02-04T16:52:08.129Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2021-27040 (GCVE-0-2021-27040)
Vulnerability from cvelistv5
Published
2021-06-25 12:41
Modified
2024-08-03 20:40
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Out-of-bound Read Vulnerability
Summary
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
References
► | URL | Tags | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022, 2021, 2020, 2019 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T20:40:46.943Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1238/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1236/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-378/" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-473/" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022, 2021, 2020, 2019" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Out-of-bound Read Vulnerability ", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-03-07T16:06:28", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1238/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1236/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-378/" }, { "tags": [ "x_refsource_MISC" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-473/" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2021-27040", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022, 2021, 2020, 2019" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Out-of-bound Read Vulnerability " } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004" }, { "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1238/", "refsource": "MISC", "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1238/" }, { "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-1236/", "refsource": "MISC", "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1236/" }, { "name": "https://www.zerodayinitiative.com/advisories/ZDI-22-378/", "refsource": "MISC", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-378/" }, { "name": "https://www.zerodayinitiative.com/advisories/ZDI-22-473/", "refsource": "MISC", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-473/" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2021-27040", "datePublished": "2021-06-25T12:41:07", "dateReserved": "2021-02-09T00:00:00", "dateUpdated": "2024-08-03T20:40:46.943Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2022-27530 (GCVE-0-2022-27530)
Vulnerability from cvelistv5
Published
2022-04-18 16:20
Modified
2024-08-03 05:32
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Buffer Overflow Write
Summary
A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D |
Version: 2022, 2021, 2020, 2019 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T05:32:59.969Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "vendor": "n/a", "versions": [ { "status": "affected", "version": "2022, 2021, 2020, 2019" } ] } ], "descriptions": [ { "lang": "en", "value": "A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code." } ], "problemTypes": [ { "descriptions": [ { "description": "Buffer Overflow Write", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-18T16:20:28", "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "shortName": "autodesk" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@autodesk.com", "ID": "CVE-2022-27530", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D", "version": { "version_data": [ { "version_value": "2022, 2021, 2020, 2019" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Buffer Overflow Write" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004", "refsource": "MISC", "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ] } } } }, "cveMetadata": { "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601", "assignerShortName": "autodesk", "cveId": "CVE-2022-27530", "datePublished": "2022-04-18T16:20:28", "dateReserved": "2022-03-21T00:00:00", "dateUpdated": "2024-08-03T05:32:59.969Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
Vulnerability from fkie_nvd
Published
2021-06-25 13:15
Modified
2024-11-21 05:57
Severity ?
Summary
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
iconics | genesis64 | * | |
mitsubishielectric | mc_works64 | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "DDC0E547-C366-4A0E-95DE-EC420492E698", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B8319413-E093-4931-B2DB-A46522DF93C9", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B350B87-23EC-44F8-9A5F-9AC815E15BD9", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAE14E69-8BCB-4E00-8BAB-CB7F1688DC27", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A084A960-35D8-4B9C-87DE-0213CA40CAD8", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "20EE0BDC-3A97-4CD4-A232-922F8D613856", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "5FDD2042-5313-4658-AA4E-109684E91C43", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE031BD1-9F02-44C2-865E-2011511B36F5", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0A51CDDA-0D83-4331-9AB6-F6ED076157F6", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "143F8B16-E253-477E-9875-94928BE5596B", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "607A4804-A286-4237-82C3-8BE98662AE20", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "967B286E-5E73-47E3-BC2F-951E26720370", "versionEndIncluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "64C50E3E-8EFA-4B0D-B284-CF8FE4129866", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBD4F808-CA46-4A8E-82DD-6D1A82DDF91C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DFD09E68-2C34-4E76-9B67-868FA6E825A6", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "08BC587D-E4C7-4758-8AF5-1970892C35C8", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "282A07AC-8D43-4580-8D2E-8E30370049F3", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "E37E4967-AC88-42D6-98C2-1BA63F20BD5C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "49512EB3-DE17-45FF-AB90-2966462A9C3C", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "01A870BA-E78E-4975-BF6D-7D410BE8CD6C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EF85630-3DDC-4026-AC5A-F1B197F98C9E", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F5309100-B3E9-4144-AEA3-B9030E93FD78", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "954682D1-2E7A-4EAB-B4B8-43E2038EB7C7", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1016D7F3-2780-4412-A7AA-361B44A8632E", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A3D0B0D7-FC6F-43D8-85AA-AC0BD464E5A1", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF6DF983-6772-45D4-A82A-EE1BB2EEFD4F", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F7ABD866-E08B-42F3-A19A-5574563AA540", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6716F29E-FBA2-4178-A8AE-269D9CC5AC59", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "372905FF-2C9B-4366-BE56-36CACDA63BCD", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2F1DCEB-7ABB-4109-943A-E2DEFB17D330", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "EA49E2B8-CBF5-4F6E-A832-D1FDB597FADE", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8CF7601F-D6A3-4CD6-961D-B8B1B82E29CE", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5F285B8D-585C-4C23-98FA-E09DE53C8247", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A10D9CEE-D92D-470D-928F-8F90243618EE", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "0199953B-BCAC-405E-BDC6-951BEAE01570", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "FBDFDF50-5230-41F1-B380-AD3EC4B53DB7", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F6A3326B-382B-4137-B0E7-0D54E825B717", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "48F67A57-7528-406B-9BF1-6A963F732564", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "825FC323-CAE7-4B39-85AD-966980D30D89", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F430EA73-2B9F-42D9-9005-42F439ABF63C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*", "matchCriteriaId": "213232B9-A40B-436D-A66A-B65C49D59BE6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*", "matchCriteriaId": "2D0CF4DC-ACA5-41D0-B28E-CEB5D2C96F71", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*", "matchCriteriaId": "84ED1789-A17F-48F7-A152-09D2A5C59254", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*", "matchCriteriaId": "74819924-EB63-4BBF-9986-FEF6100EEE15", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:*", "matchCriteriaId": "100922EF-C773-4798-B352-B16FCAD48F36", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:iconics:genesis64:*:*:*:*:*:*:*:*", "matchCriteriaId": "EC66E916-D8A4-475B-A7E3-4E2FEF46A7B9", "versionEndIncluding": "10.97", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:mitsubishielectric:mc_works64:*:*:*:*:*:*:*:*", "matchCriteriaId": "AAE9E820-2348-4895-9F7D-96071747109D", "versionEndIncluding": "4.04e", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code" }, { "lang": "es", "value": "Un archivo DWG malicioso puede ser utilizado para escribir m\u00e1s all\u00e1 del buffer asignado mientras se analizan los archivos DWG. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2021-27041", "lastModified": "2024-11-21T05:57:14.057", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-06-25T13:15:08.217", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un CATPART, X_B y STEP creados con fines malintencionados, cuando se analizan en ASMKERN228A.dll y ASMKERN229A.dll a trav\u00e9s de aplicaciones de Autodesk, pueden provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23147", "lastModified": "2025-05-06T19:56:54.603", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.190", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 17:18
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo X_B y X_T creado con fines malintencionados, cuando se analiza en pskernel.DLL a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de use-after-free. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-37007", "lastModified": "2025-05-06T17:18:01.147", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:16.170", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-10-29 21:15
Modified
2024-12-16 00:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0019 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2025 | |
autodesk | autocad | 2025 | |
autodesk | autocad_architecture | 2025 | |
autodesk | autocad_electrical | 2025 | |
autodesk | autocad_mechanical | 2025 | |
autodesk | autocad_mep | 2025 | |
autodesk | autocad_plant_3d | 2025 | |
autodesk | civil_3d | 2025 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*", "matchCriteriaId": "B26ECB1F-375C-4695-BD06-F9752CBADFC6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*", "matchCriteriaId": "E131B949-522C-4898-8375-BEF88C77E5F6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*", "matchCriteriaId": "DA34F55E-6539-46C3-848D-7A0373D373F5", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*", "matchCriteriaId": "C288215A-6B64-403C-B955-87A61AEAACE1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*", "matchCriteriaId": "E8EEB057-008A-4E7C-B90F-0661CB00FED0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*", "matchCriteriaId": "C1370F96-D4C1-40B2-8890-8C652D5BE0D3", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*", "matchCriteriaId": "1848ABD0-D516-481F-B2FF-27DC657B37AD", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*", "matchCriteriaId": "77FBAF4B-88C6-4C7D-BEF3-F7C8095ADF7F", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": " Un archivo SLDPRT creado con fines malintencionados, cuando se analiza en odxsw_dll.dll a trav\u00e9s de Autodesk AutoCAD, puede provocar una vulnerabilidad de desbordamiento de b\u00fafer de almacenamiento din\u00e1mico. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-8587", "lastModified": "2024-12-16T00:15:04.950", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2024-10-29T21:15:04.990", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0019" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede generar una vulnerabilidad de uso despu\u00e9s de la liberaci\u00f3n. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-6636", "lastModified": "2025-08-19T14:15:42.533", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:32.350", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2021-06-25 13:15
Modified
2024-11-21 05:57
Severity ?
Summary
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "DDC0E547-C366-4A0E-95DE-EC420492E698", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B8319413-E093-4931-B2DB-A46522DF93C9", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B350B87-23EC-44F8-9A5F-9AC815E15BD9", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAE14E69-8BCB-4E00-8BAB-CB7F1688DC27", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A084A960-35D8-4B9C-87DE-0213CA40CAD8", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "20EE0BDC-3A97-4CD4-A232-922F8D613856", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "5FDD2042-5313-4658-AA4E-109684E91C43", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE031BD1-9F02-44C2-865E-2011511B36F5", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0A51CDDA-0D83-4331-9AB6-F6ED076157F6", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "143F8B16-E253-477E-9875-94928BE5596B", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "607A4804-A286-4237-82C3-8BE98662AE20", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "967B286E-5E73-47E3-BC2F-951E26720370", "versionEndIncluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "64C50E3E-8EFA-4B0D-B284-CF8FE4129866", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBD4F808-CA46-4A8E-82DD-6D1A82DDF91C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DFD09E68-2C34-4E76-9B67-868FA6E825A6", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "08BC587D-E4C7-4758-8AF5-1970892C35C8", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "282A07AC-8D43-4580-8D2E-8E30370049F3", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "E37E4967-AC88-42D6-98C2-1BA63F20BD5C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "49512EB3-DE17-45FF-AB90-2966462A9C3C", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "01A870BA-E78E-4975-BF6D-7D410BE8CD6C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EF85630-3DDC-4026-AC5A-F1B197F98C9E", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F5309100-B3E9-4144-AEA3-B9030E93FD78", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "954682D1-2E7A-4EAB-B4B8-43E2038EB7C7", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1016D7F3-2780-4412-A7AA-361B44A8632E", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A3D0B0D7-FC6F-43D8-85AA-AC0BD464E5A1", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF6DF983-6772-45D4-A82A-EE1BB2EEFD4F", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F7ABD866-E08B-42F3-A19A-5574563AA540", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6716F29E-FBA2-4178-A8AE-269D9CC5AC59", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "372905FF-2C9B-4366-BE56-36CACDA63BCD", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2F1DCEB-7ABB-4109-943A-E2DEFB17D330", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "EA49E2B8-CBF5-4F6E-A832-D1FDB597FADE", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8CF7601F-D6A3-4CD6-961D-B8B1B82E29CE", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5F285B8D-585C-4C23-98FA-E09DE53C8247", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A10D9CEE-D92D-470D-928F-8F90243618EE", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "0199953B-BCAC-405E-BDC6-951BEAE01570", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "FBDFDF50-5230-41F1-B380-AD3EC4B53DB7", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F6A3326B-382B-4137-B0E7-0D54E825B717", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "48F67A57-7528-406B-9BF1-6A963F732564", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "825FC323-CAE7-4B39-85AD-966980D30D89", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F430EA73-2B9F-42D9-9005-42F439ABF63C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code." }, { "lang": "es", "value": "Un archivo DWG dise\u00f1ado maliciosamente puede ser usado para escribir m\u00e1s all\u00e1 del b\u00fafer asignado mientras se analizan los archivos DWG. La vulnerabilidad se presenta porque la aplicaci\u00f3n comete un fallo para manejar un archivo DWG dise\u00f1ado, lo que causa una excepci\u00f3n no manejada. Un atacante puede aprovechar esta vulnerabilidad para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2021-27042", "lastModified": "2024-11-21T05:57:14.187", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-06-25T13:15:08.247", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-755" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2021-12-23 19:15
Modified
2024-11-21 06:23
Severity ?
Summary
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010 | Patch, Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010 | Patch, Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | navisworks | * | |
autodesk | navisworks | * | |
autodesk | navisworks | * | |
autodesk | navisworks | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | 2020 | |
autodesk | autocad | 2021 | |
autodesk | autocad | 2022 | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | 2020 | |
autodesk | autocad_lt | 2021 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "8579FBF7-DA4C-48D2-8F9A-2D96D1CBF9A0", "versionEndExcluding": "2020.2.5", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "26E05A0E-6DBE-4DC0-A491-2A4419EA8835", "versionEndExcluding": "2021.1.6", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "3F027164-A465-47C3-B92C-56A9D8759905", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "9AFAEAD3-55FC-4918-8B74-B78975266C82", "versionEndExcluding": "2019.6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "FB5C1908-9829-46DE-881F-57277490BE71", "versionEndExcluding": "2020.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE821566-76A8-43D6-9628-B82CFE9FAC19", "versionEndExcluding": "2021.3", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "7AAFCE8D-C6FA-4179-BBD8-134F91261FEC", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "63ABBBCD-A869-47D6-BBBF-30E03F0DCC33", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0203EC49-7943-4759-B62D-334FAF6B7A83", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87941CE7-7F89-4A09-BBE8-A0D829273A63", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F98B75B-1471-42A7-BCDA-95F7E65B7FD1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1E40E1E-9B7F-4DB9-BB85-2832297135BC", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "D23CAABD-FB77-4365-B7BC-4330315672AA", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1BA4DE9-CCBC-4A08-B6C8-F50490BA2283", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8167B5BF-1B06-414F-9088-A126D7C06515", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "117BA468-7345-4FEA-A0E3-D4110F7472C3", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7D8E7984-95F9-4FF4-AEBB-D60DF9F83D65", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "61A9231D-C524-49F5-A8D1-7D70D8034F5D", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "0E59ACB5-8745-46A8-889E-005DEA38925B", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "CFFE146F-4AB2-45B2-9F87-52DD8DC26B85", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1885BB08-EF19-4780-92F0-1ED4B18F0DB3", "versionEndExcluding": "2019.1.4", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "9E2CC26F-F7B5-4BA6-A243-B22A37347A42", "versionEndExcluding": "2022.2", "versionStartExcluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2020:*:*:*:*:macos:*:*", "matchCriteriaId": "5EF0E224-30B2-4A78-89A8-036304BBCE48", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:macos:*:*", "matchCriteriaId": "2FB00DBF-2EC2-433F-9987-189729A46314", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:macos:*:*", "matchCriteriaId": "68FC54D1-B4FC-404E-9742-72F8340FE3C7", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "FF16B57E-C704-43BE-94F5-F09493257323", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2020:*:*:*:*:macos:*:*", "matchCriteriaId": "FC750C20-98CA-401E-B0AF-5013CE9CB319", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2021:*:*:*:*:macos:*:*", "matchCriteriaId": "164EB7AD-8B17-48E1-A73D-5E5D0012B360", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*", "matchCriteriaId": "213232B9-A40B-436D-A66A-B65C49D59BE6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*", "matchCriteriaId": "2D0CF4DC-ACA5-41D0-B28E-CEB5D2C96F71", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*", "matchCriteriaId": "84ED1789-A17F-48F7-A152-09D2A5C59254", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*", "matchCriteriaId": "74819924-EB63-4BBF-9986-FEF6100EEE15", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:*", "matchCriteriaId": "100922EF-C773-4798-B352-B16FCAD48F36", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version." }, { "lang": "es", "value": "Una vulnerabilidad de corrupci\u00f3n de memoria puede conducir a la ejecuci\u00f3n de c\u00f3digo a trav\u00e9s de archivos DLL maliciosamente dise\u00f1ados a trav\u00e9s de PDFTron anterior a la versi\u00f3n 9.0.7" } ], "id": "CVE-2021-40161", "lastModified": "2024-11-21T06:23:41.847", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.4, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 3.4, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-12-23T19:15:12.167", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Patch", "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 05:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo IGS creado con fines malintencionados cuando tbb.dll se analiza a trav\u00e9s de Autodesk AutoCAD se puede utilizar en una vulnerabilidad de user-after-free. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23134", "lastModified": "2025-04-11T15:56:01.183", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T05:15:09.187", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:47
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL creado con fines malintencionados, cuando se analiza en libodx.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23153", "lastModified": "2025-05-06T19:47:39.307", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:12.953", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-19 21:15
Modified
2024-11-21 06:53
Severity ?
Summary
A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | inventor | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "E3116E10-FB93-4EC7-957E-B130FE5153BF", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "0DC17B10-E6E8-4D49-BDEF-DBC5097580C9", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "EEC464C9-D741-41B4-B460-B4305BCD83FA", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*", "matchCriteriaId": "D53B7E4C-4F2E-428D-A6CB-D4F2FB5865B0", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code." }, { "lang": "es", "value": "Un archivo JT malicioso en Autodesk AutoCAD versi\u00f3n 2022 puede usarse para escribir m\u00e1s all\u00e1 del b\u00fafer asignado mientras son analizados los archivos JT. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2022-25788", "lastModified": "2024-11-21T06:53:00.200", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-19T21:15:18.650", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 03:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPART creado con fines malintencionados cuando se analiza CC5Dll.dll a trav\u00e9s de Autodesk AutoCAD se puede utilizar para provocar un desbordamiento en la regi\u00f3n stack de la memoria. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23126", "lastModified": "2025-04-11T15:57:09.833", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T03:15:08.170", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-121" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 03:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL, SLDPRT o SLDASM creado con fines malintencionados cuando se analiza VCRUNTIME140.dll a trav\u00e9s de Autodesk AutoCAD se puede utilizar para provocar un desbordamiento de b\u00fafer de almacenamiento din\u00e1mico. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23127", "lastModified": "2025-04-11T15:56:55.197", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T03:15:08.233", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo SLDPRT manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede generar una vulnerabilidad de corrupci\u00f3n de memoria. Un agente malicioso puede aprovechar esta vulnerabilidad para ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1430", "lastModified": "2025-08-19T13:15:40.863", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.217", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-120" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:34
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo SLDPRT creado con fines malintencionados, cuando se analiza en ASMKERN229A.dll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de use-after-free. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-37004", "lastModified": "2025-05-06T19:34:44.290", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:15.567", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2019-04-09 20:30
Modified
2024-11-21 04:48
Severity ?
Summary
An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file with too many cell margins populating an AcCellMargin object may cause a heap overflow, resulting in code execution.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2018 | |
autodesk | autocad | 2018 | |
autodesk | autocad_architecture | 2018 | |
autodesk | autocad_electrical | 2018 | |
autodesk | autocad_lt | 2018 | |
autodesk | autocad_map_3d | 2018 | |
autodesk | autocad_mechanical | 2018 | |
autodesk | autocad_mep | 2018 | |
autodesk | autocad_p\&id | 2018 | |
autodesk | autocad_plant_3d | 2018 | |
autodesk | civil_3d | 2018 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2018:*:*:*:*:*:*:*", "matchCriteriaId": "461B3C59-740C-4530-80DA-23DD38A0EEB7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2018:*:*:*:*:*:*:*", "matchCriteriaId": "4C2610D4-81E7-4B85-9147-C3F24895EDB0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2018:*:*:*:*:*:*:*", "matchCriteriaId": "ECDE64CF-3527-4C9A-9672-E2FA3BCC8B65", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "FC2B0DF8-8827-4CF2-94F1-D2871FA5095F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2018:*:*:*:*:*:*:*", "matchCriteriaId": "85BF0890-5AE7-46BA-8FD4-667B20081A0C", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "F4C4F749-A0C3-4C25-B5FC-CE3E49AFF8F6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "E34DF2FB-6A4F-4060-9DE4-EE635D9056E8", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2018:*:*:*:*:*:*:*", "matchCriteriaId": "BA943872-F736-4EC2-8328-9AABCAE08154", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_p\\\u0026id:2018:*:*:*:*:*:*:*", "matchCriteriaId": "B80C406D-9E82-4B2B-8065-FEB797DE65B1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "68F6B255-EE77-48BA-AEEE-9395C85BF274", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "2692C0E3-9A82-42BA-A80D-8A0D72FD3164", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file with too many cell margins populating an AcCellMargin object may cause a heap overflow, resulting in code execution." }, { "lang": "es", "value": "Una vulnerabilidad explotable de desbordamiento de pila en el c\u00f3digo de manejo AcCellMargin en Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD , Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018 y Autodesk Civil 3D 2018. Un archivo DXF especialmente creado con muchos m\u00e1rgenes de celda que pueblan un objeto AcCellMargin puede generar un desbordamiento de pila, lo que conlleva a la ejecuci\u00f3n del c\u00f3digo." } ], "id": "CVE-2019-7359", "lastModified": "2024-11-21T04:48:05.663", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2019-04-09T20:30:21.287", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 00:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo STP, CATPART o MODEL creado con fines malintencionados cuando se analiza en ASMKERN228A.dll a trav\u00e9s de Autodesk AutoCAD puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-0446", "lastModified": "2025-04-11T15:57:56.020", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T00:15:51.903", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 03:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo SLDPRT creado con fines malintencionados cuando se analiza ODXSW_DLL.dll a trav\u00e9s de Autodesk AutoCAD se puede utilizar para provocar un desbordamiento en la regi\u00f3n stack de la memoria. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23125", "lastModified": "2025-04-11T15:57:00.697", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T03:15:08.100", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-121" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:44
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados, cuando se analiza en stp_aim_x64_vc15d.dll a trav\u00e9s de aplicaciones de Autodesk, se puede utilizar para variables no inicializadas. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23159", "lastModified": "2025-05-06T19:44:19.393", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:14.203", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-908" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 14:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de lectura fuera de los l\u00edmites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1652", "lastModified": "2025-08-19T14:15:37.177", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:36.297", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT creado con fines malintencionados, cuando se analiza en opennurbs.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23145", "lastModified": "2025-05-06T19:56:29.470", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.000", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:58
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo X_B creado con fines malintencionados, cuando se analiza en pskernel.DLL a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-37000", "lastModified": "2025-05-06T19:58:18.400", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.463", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:43
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo SLDASM o SLDPRT creado con fines malintencionados, cuando se analiza en ODXSW_DLL.dll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23157", "lastModified": "2025-05-06T19:43:31.060", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:13.723", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:45
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "[Un archivo 3DM creado con fines malintencionados, cuando se analiza en opennurbs.dll a trav\u00e9s de aplicaciones de Autodesk, se puede utilizar para provocar un desbordamiento basado en mont\u00f3n. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-37001", "lastModified": "2025-05-06T19:45:05.107", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.553", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 05:15
Modified
2025-04-11 15:55
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo SLDPRT creado con fines malintencionados cuando ASMkern228A.dll se analiza a trav\u00e9s de Autodesk AutoCAD se puede utilizar en una vulnerabilidad de user-after-free. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23135", "lastModified": "2025-04-11T15:55:36.260", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T05:15:09.357", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 14:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPRODUCT manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de variable no inicializada. Un agente malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1649", "lastModified": "2025-08-19T14:15:36.613", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.837", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-908" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2021-12-23 19:15
Modified
2024-11-21 06:23
Severity ?
Summary
PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010 | Patch, Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010 | Patch, Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | navisworks | * | |
autodesk | navisworks | * | |
autodesk | navisworks | * | |
autodesk | navisworks | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 | |
autodesk | design_review | 2018 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DCAF9B0-8B1F-4625-B04F-DECB699C9770", "versionEndExcluding": "2020.2.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "A9BBB8FC-C689-4DF6-B79D-248C0144A5EC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "A29624C7-516C-4E7E-B1FE-43ED3188BC70", "versionEndExcluding": "2022.1", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "70EC1A64-F7DD-4835-969F-A9051F06CB60", "versionEndExcluding": "2019.6", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "FB5C1908-9829-46DE-881F-57277490BE71", "versionEndExcluding": "2020.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE821566-76A8-43D6-9628-B82CFE9FAC19", "versionEndExcluding": "2021.3", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "CE0E4388-28DB-4D72-BA69-882A121C8C9A", "versionEndExcluding": "2022.1", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "67E62F6D-C9D2-4129-A25A-468F150BA2CB", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4104E0A8-E133-41F9-A60A-368FD2DCC1A3", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "F7B0B566-F23E-4637-8611-8D055A90F421", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "D42D33AA-39DC-4B60-A87F-2B9A41390EDA", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2D4CB47-D77A-4ACA-A606-3E7880729E0C", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "E813870A-AAB5-491F-8ECA-587432AD9935", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "FF16B57E-C704-43BE-94F5-F09493257323", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1172D845-0F80-45EC-95D6-911556D4032D", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "047BD11C-74A7-47AA-A593-BAACD00D2B89", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "C926403A-E06B-45A7-9693-CF0B78C7C627", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C3807591-D6E0-4BB6-9573-C318A9D4EF60", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B4C8F3C7-F830-4138-99BD-064F969E4929", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:-:*:*:*:*:*:*", "matchCriteriaId": "213232B9-A40B-436D-A66A-B65C49D59BE6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix:*:*:*:*:*:*", "matchCriteriaId": "2D0CF4DC-ACA5-41D0-B28E-CEB5D2C96F71", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix2:*:*:*:*:*:*", "matchCriteriaId": "84ED1789-A17F-48F7-A152-09D2A5C59254", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix3:*:*:*:*:*:*", "matchCriteriaId": "74819924-EB63-4BBF-9986-FEF6100EEE15", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:design_review:2018:hotfix4:*:*:*:*:*:*", "matchCriteriaId": "100922EF-C773-4798-B352-B16FCAD48F36", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code." }, { "lang": "es", "value": "PDFTron antes de la versi\u00f3n 9.0.7 puede ser forzado a leer m\u00e1s all\u00e1 de los l\u00edmites asignados al analizar un archivo PDF malicioso. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2021-40160", "lastModified": "2024-11-21T06:23:41.700", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-12-23T19:15:12.117", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Patch", "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.1 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
7.1 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Summary
A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo SLDDRW creado con fines malintencionados, cuando se analiza en ODXSW_DLL.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23149", "lastModified": "2025-05-06T19:57:57.397", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.1, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.2, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.370", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:46
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
5.5 (Medium) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5 (Medium) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM creado con fines malintencionados, cuando se analiza en opennurbs.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23152", "lastModified": "2025-05-06T19:46:18.960", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 5.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 3.6, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:12.770", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 02:15
Modified
2025-05-06 19:55
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM, MODEL y X_B creado con fines malintencionados, cuando se analiza en ASMkern229A.dll y ASMBASE229A.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites y/o una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23143", "lastModified": "2025-05-06T19:55:47.810", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T02:15:11.203", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" }, { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo SLDPRT manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de lectura fuera de los l\u00edmites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1431", "lastModified": "2025-08-19T13:15:41.053", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.377", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-04-15 21:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * | |
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "EA981919-DECA-40F1-AC6C-588C3A128F58", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "02B8E71C-23B5-4D6B-A14F-4F292D71AEDB", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "20F2CF70-28C1-42E3-B48B-469AACC245E0", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "CB3814C7-89F1-4769-A667-8A941FECFECA", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "B5615AA3-02AB-41E6-B207-C8E2BF14381B", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "68D32CA8-DAE5-454E-9611-6DC7D39936B6", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "3EA52EB6-C7F7-4CAF-9932-6E434F6AF08F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "5F61D5DA-0CBA-4A14-8CD4-154FFE14E70C", "versionEndExcluding": "2024.3.2", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "4229BAB4-AE43-43E3-89ED-1E19445482E1", "versionEndExcluding": "2025.4.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo JPG manipulado con fines maliciosos, al vincularse o importarse a ciertas aplicaciones de Autodesk, puede generar una vulnerabilidad de desbordamiento basado en mont\u00f3n. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1275", "lastModified": "2025-08-19T13:15:39.617", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-04-15T21:15:47.197", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/dwg-trueview/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0006" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPRODUCT creado con fines malintencionados, cuando se analiza en CC5Dll.dll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23148", "lastModified": "2025-05-06T19:57:10.507", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.283", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 04:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL creado con fines malintencionados en libodxdll.dll cuando se analiza mediante Autodesk AutoCAD podr\u00eda provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23128", "lastModified": "2025-04-11T15:56:46.490", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T04:15:08.590", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:34
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DWG y SLDPRT creado con fines malintencionados, cuando se analiza en opennurbs.dll y ODXSW_DLL.dll a trav\u00e9s de aplicaciones de Autodesk, se puede utilizar para provocar un desbordamiento basado en pila. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-37003", "lastModified": "2025-05-06T19:34:18.483", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:15.370", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-121" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 05:15
Modified
2025-04-11 15:55
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo STP o SLDPRT creado con fines malintencionados cuando ODXSW_DLL.dll se analiza mediante Autodesk AutoCAD se puede utilizar para variables no inicializadas. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23137", "lastModified": "2025-04-11T15:55:06.557", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T05:15:09.640", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-908" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 02:15
Modified
2025-05-06 19:49
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM y MODEL creado con fines malintencionados, cuando se analiza en opennurbs.dll y atf_api.dll mediante aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23140", "lastModified": "2025-05-06T19:49:48.133", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T02:15:10.940", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-08-15 15:15
Modified
2025-08-20 21:21
Severity ?
Summary
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_lt | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*", "matchCriteriaId": "51F919FB-6AFC-43FF-91C4-DC15FCF5B6EF", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DGN manipulado con fines maliciosos, al vincularse o importarse a Autodesk AutoCAD, puede forzar una vulnerabilidad de lectura fuera de los l\u00edmites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-5046", "lastModified": "2025-08-20T21:21:15.320", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Primary" } ] }, "published": "2025-08-15T15:15:32.973", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Product" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 04:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL 3DM, STP o SLDASM creado con fines malintencionados en opennurbs.dll cuando se analiza a trav\u00e9s de Autodesk AutoCAD podr\u00eda provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23129", "lastModified": "2025-04-11T15:56:40.640", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T04:15:08.667", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 00:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados cuando se analiza en ASMIMPORT228A.dll a trav\u00e9s de Autodesk AutoCAD puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23120", "lastModified": "2025-04-11T15:57:41.513", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T00:15:52.510", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo X_T manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede generar una vulnerabilidad de corrupci\u00f3n de memoria. Un agente malicioso puede aprovechar esta vulnerabilidad para ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-5038", "lastModified": "2025-08-19T14:15:40.623", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:31.590", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-120" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-08-20 00:15
Modified
2025-07-30 17:26
Severity ?
Summary
A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0014 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "83E49B24-F309-4316-8F6A-E3E851E11842", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "D98FDFB4-A393-43CF-BB2F-E7DE8F6414F7", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "BAA7DE4E-9D9D-4A3C-9813-1ECA420CA55D", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "4B431A85-E752-468C-B79C-B8EA117B595A", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "C716D385-CF42-4447-8F2F-B39E54014F9C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "31DB9D22-B7DF-4665-B3A0-DA9F36E5C458", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2F1B47DF-B1A3-4F55-9373-F3FA48E38A52", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "A7D5DE8F-7CAB-4E44-9E65-70DE939B0737", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "3B8C034F-57BD-4F6D-B6F0-904FC1212CBB", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "A423FC2B-E95C-480B-B187-3560C87FC5EE", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "44E0813A-0AB6-4708-BB81-BED56A1DB52F", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8A527B57-2244-4A02-96C7-D353C1C43655", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "EFCF8E88-0CA5-4E6F-9A16-3847D339EF73", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4780EE8D-48FC-4525-B5E2-0F0D7274BBA6", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "658A341D-D3E0-4C49-99E6-D1A3D50F6101", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "87BB7922-C51A-470E-8737-3306C9B85915", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "CB3814C7-89F1-4769-A667-8A941FECFECA", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "A1EBB2BC-6606-451A-A348-21D7A2BD0051", "versionEndExcluding": "2024.1.6", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "54416738-6C97-4ED3-A982-111C93576C33", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DWF creado con fines malintencionados, cuando se analiza en AdDwfPdk.dll a trav\u00e9s de Autodesk AutoCAD, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-7305", "lastModified": "2025-07-30T17:26:19.867", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2024-08-20T00:15:04.003", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0014" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 02:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM creado con fines malintencionados, cuando se analiza en opennurbs.dll a trav\u00e9s de Autodesk AutoCAD, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23122", "lastModified": "2025-04-11T15:57:29.043", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T02:15:49.363", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:43
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL creado con fines malintencionados, cuando se analiza en atf_asm_interface.dll a trav\u00e9s de aplicaciones de Autodesk, se puede utilizar para provocar un desbordamiento de b\u00fafer basado en mont\u00f3n. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23155", "lastModified": "2025-05-06T19:43:00.537", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:13.330", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-03-18 00:15
Modified
2025-07-29 20:18
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "2CE80096-77E4-4513-BB5C-29131A3152B6", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "882B6D39-9809-44FC-BFA1-DD06A1013D84", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "F696A239-23BA-4298-88C2-F4D8DFAB9665", "versionEndExcluding": "2022.4.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "D796D139-2335-49D9-8313-49E2ACAFE45D", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "EEFDD1A0-CE86-44C0-A458-F0F55CC002DC", "versionEndExcluding": "2023.3.1", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "1BF8849B-7768-4047-A94C-2B061791DBB2", "versionEndExcluding": "2024.1.2", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "6ED58CFD-2634-4F69-82C6-A31577DCFE7A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6D3CC3BA-E749-47B0-9FF3-79D7624E83F3", "versionEndIncluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "38B59283-8F7B-411E-AE65-93C2B8B5436D", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "F8344E03-8CE1-44F0-BDB4-E8CDFEFB962F", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "A5B205C4-3421-4FEC-A511-B71C13B1F5FD", "versionEndExcluding": "2022.4.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "ED05CDAD-6EB5-4BCB-84ED-EA40C44CF0D2", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "BEE02035-D1ED-43DC-8A3B-F1679ADA9612", "versionEndExcluding": "2023.3.1", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "FC50A1F5-0B8D-4CC2-9D0D-6DDF45B564D5", "versionEndExcluding": "2024.1.2", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "5D9B13E6-B8AB-49C0-9342-A44CA98A17C6", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "071BACC3-C689-409D-8E2E-DBEB3B2C6812", "versionEndExcluding": "2023.15", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "91A06CFB-3C31-443C-8891-627676314EDD", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "5D5198DB-A584-4FD6-9CC0-316799589D2C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "F79AA6BE-4578-4914-A3BB-BD341A6A485F", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DWG creado con fines malintencionados cuando se analiza mediante Autodesk DWG TrueView se puede utilizar para provocar un desbordamiento en la regi\u00f3n stack de la memoria . Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23138", "lastModified": "2025-07-29T20:18:29.323", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-03-18T00:15:07.587", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0006" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0006" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-121" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:46
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM creado con fines malintencionados, cuando se analiza en ASMkern229A.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23151", "lastModified": "2025-05-06T19:46:04.660", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:12.567", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los l\u00edmites. Un agente malicioso podr\u00eda aprovechar esta vulnerabilidad para provocar un bloqueo, da\u00f1ar datos o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-6631", "lastModified": "2025-08-19T14:15:41.790", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:31.983", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2019-04-09 20:30
Modified
2024-11-21 04:48
Severity ?
Summary
An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2018 | |
autodesk | autocad | 2018 | |
autodesk | autocad_architecture | 2018 | |
autodesk | autocad_electrical | 2018 | |
autodesk | autocad_lt | 2018 | |
autodesk | autocad_map_3d | 2018 | |
autodesk | autocad_mechanical | 2018 | |
autodesk | autocad_mep | 2018 | |
autodesk | autocad_p\&id | 2018 | |
autodesk | autocad_plant_3d | 2018 | |
autodesk | civil_3d | 2018 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2018:*:*:*:*:*:*:*", "matchCriteriaId": "461B3C59-740C-4530-80DA-23DD38A0EEB7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2018:*:*:*:*:*:*:*", "matchCriteriaId": "4C2610D4-81E7-4B85-9147-C3F24895EDB0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2018:*:*:*:*:*:*:*", "matchCriteriaId": "ECDE64CF-3527-4C9A-9672-E2FA3BCC8B65", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "FC2B0DF8-8827-4CF2-94F1-D2871FA5095F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2018:*:*:*:*:*:*:*", "matchCriteriaId": "85BF0890-5AE7-46BA-8FD4-667B20081A0C", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "F4C4F749-A0C3-4C25-B5FC-CE3E49AFF8F6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "E34DF2FB-6A4F-4060-9DE4-EE635D9056E8", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2018:*:*:*:*:*:*:*", "matchCriteriaId": "BA943872-F736-4EC2-8328-9AABCAE08154", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_p\\\u0026id:2018:*:*:*:*:*:*:*", "matchCriteriaId": "B80C406D-9E82-4B2B-8065-FEB797DE65B1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "68F6B255-EE77-48BA-AEEE-9395C85BF274", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "2692C0E3-9A82-42BA-A80D-8A0D72FD3164", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018." }, { "lang": "es", "value": "Un atacante puede convencer a una v\u00edctima para abrir un archivo micro de acci\u00f3n maliciosa (.actm) que tiene datos serializados, lo que puede desencadenar una ejecuci\u00f3n de c\u00f3digo en Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P \u0026 ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018 y Autodesk Civil 3D 2018." } ], "id": "CVE-2019-7361", "lastModified": "2024-11-21T04:48:05.923", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2019-04-09T20:30:21.383", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-502" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo X_B y X_T creado con fines malintencionados, cuando se analiza en pskernel.DLL a trav\u00e9s de aplicaciones de Autodesk, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23146", "lastModified": "2025-05-06T19:56:40.253", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.093", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 02:15
Modified
2025-05-06 19:52
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo CATPART, STP y MODEL creado con fines malintencionados, cuando se analiza en atf_dwg_consumer.dll, rose_x64_vc15.dll y libodxdll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de use-after-free. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23142", "lastModified": "2025-05-06T19:52:06.397", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T02:15:11.123", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-11 20:15
Modified
2024-11-21 06:53
Severity ?
Summary
A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "395D75D7-FE8C-461D-8642-98BE81AA5277", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "B0E84020-F179-4AF3-BF9C-6D27259B2847", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87941CE7-7F89-4A09-BBE8-A0D829273A63", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F98B75B-1471-42A7-BCDA-95F7E65B7FD1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "C9338B09-BCD8-4E67-A331-1B8D5FB5DA24", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "86CF88E0-A49D-4528-8135-6BE5C9E5DD7C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "77A1562A-07B8-4130-B319-1BE2800D8771", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "0E59ACB5-8745-46A8-889E-005DEA38925B", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "CFFE146F-4AB2-45B2-9F87-52DD8DC26B85", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "230F8974-9613-4B58-8621-67CCE81E208C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF0FCE36-8A0F-4CDB-86B3-D8F7875511FD", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "1075AC6C-C9E1-45EA-B371-B06235C6AA86", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C71A1AD7-4651-4FA9-9114-023E07DCB285", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6929C4B1-27A0-4595-ABB6-48BB7F03A3EB", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution." }, { "lang": "es", "value": "Los archivos DWF, 3DS y DWFX dise\u00f1ados de forma maliciosa en Autodesk AutoCAD versiones 2022, 2021, 2020, 2019, pueden usarse para desencadenar una vulnerabilidad de uso de memoria previamente liberada. Una explotaci\u00f3n de esta vulnerabilidad puede conllevar a una ejecuci\u00f3n de c\u00f3digo" } ], "id": "CVE-2022-25789", "lastModified": "2024-11-21T06:53:00.313", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-11T20:15:20.460", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 04:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo SLDASM o SLDPRT creado con fines malintencionados en ODXSW_DLL.dll cuando se analiza a trav\u00e9s de Autodesk AutoCAD podr\u00eda provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23130", "lastModified": "2025-04-11T15:56:32.503", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T04:15:08.737", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-08-15 15:15
Modified
2025-08-20 21:22
Severity ?
Summary
A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_lt | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*", "matchCriteriaId": "51F919FB-6AFC-43FF-91C4-DC15FCF5B6EF", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DGN manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de variable no inicializada. Un agente malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-5047", "lastModified": "2025-08-20T21:22:21.610", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Primary" } ] }, "published": "2025-08-15T15:15:33.153", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Product" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-18 17:15
Modified
2024-11-21 06:55
Severity ?
Summary
A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "395D75D7-FE8C-461D-8642-98BE81AA5277", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "41A08A1E-5CC8-4F1A-8485-871366315BAC", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "A8B6181F-DFD8-4105-B277-95729F8EF34F", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "B234B44D-C528-4213-AE32-DEED2EC472F1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "E3116E10-FB93-4EC7-957E-B130FE5153BF", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "C9338B09-BCD8-4E67-A331-1B8D5FB5DA24", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "86CF88E0-A49D-4528-8135-6BE5C9E5DD7C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "04AF77FA-C980-47ED-B4C5-EEA965D425DF", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "F5783F63-D6BF-44BB-8001-3134D4CD5CF0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "3E1AB702-ABBD-4110-9B27-F4C2EC3F6A00", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "0DC17B10-E6E8-4D49-BDEF-DBC5097580C9", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "EEC464C9-D741-41B4-B460-B4305BCD83FA", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "230F8974-9613-4B58-8621-67CCE81E208C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF0FCE36-8A0F-4CDB-86B3-D8F7875511FD", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "1075AC6C-C9E1-45EA-B371-B06235C6AA86", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C71A1AD7-4651-4FA9-9114-023E07DCB285", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6929C4B1-27A0-4595-ABB6-48BB7F03A3EB", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code." }, { "lang": "es", "value": "Un archivo PICT, BMP, PSD o TIF dise\u00f1ado de forma maliciosa en Autodesk AutoCAD versiones 2022, 2021, 2020, 2019, puede usarse para escribir m\u00e1s all\u00e1 del b\u00fafer asignado mientras es analizado un archivo PICT, BMP, PSD o TIF. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2022-27529", "lastModified": "2024-11-21T06:55:53.340", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-18T17:15:16.897", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT manipulado con fines maliciosos, al vincularse o importarse a ciertos productos de Autodesk, puede generar una vulnerabilidad de lectura fuera de los l\u00edmites. Un agente malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-6635", "lastModified": "2025-08-19T14:15:42.380", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:32.170", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM manipulado con fines maliciosos, al vincularse o importarse a ciertos productos de Autodesk, puede generar una vulnerabilidad de desbordamiento basado en mont\u00f3n. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-5043", "lastModified": "2025-08-19T14:15:41.273", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:31.783", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2019-04-09 20:30
Modified
2024-11-21 04:48
Severity ?
Summary
An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2018 | |
autodesk | autocad | 2018 | |
autodesk | autocad_architecture | 2018 | |
autodesk | autocad_electrical | 2018 | |
autodesk | autocad_lt | 2018 | |
autodesk | autocad_map_3d | 2018 | |
autodesk | autocad_mechanical | 2018 | |
autodesk | autocad_mep | 2018 | |
autodesk | autocad_p\&id | 2018 | |
autodesk | autocad_plant_3d | 2018 | |
autodesk | civil_3d | 2018 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2018:*:*:*:*:*:*:*", "matchCriteriaId": "461B3C59-740C-4530-80DA-23DD38A0EEB7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2018:*:*:*:*:*:*:*", "matchCriteriaId": "4C2610D4-81E7-4B85-9147-C3F24895EDB0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2018:*:*:*:*:*:*:*", "matchCriteriaId": "ECDE64CF-3527-4C9A-9672-E2FA3BCC8B65", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "FC2B0DF8-8827-4CF2-94F1-D2871FA5095F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2018:*:*:*:*:*:*:*", "matchCriteriaId": "85BF0890-5AE7-46BA-8FD4-667B20081A0C", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "F4C4F749-A0C3-4C25-B5FC-CE3E49AFF8F6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "E34DF2FB-6A4F-4060-9DE4-EE635D9056E8", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2018:*:*:*:*:*:*:*", "matchCriteriaId": "BA943872-F736-4EC2-8328-9AABCAE08154", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_p\\\u0026id:2018:*:*:*:*:*:*:*", "matchCriteriaId": "B80C406D-9E82-4B2B-8065-FEB797DE65B1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "68F6B255-EE77-48BA-AEEE-9395C85BF274", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "2692C0E3-9A82-42BA-A80D-8A0D72FD3164", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may trigger a use-after-free, resulting in code execution." }, { "lang": "es", "value": "Una vulnerabilidad explotable de uso de memoria previamente liberada (use-after-free) de la funcionalidad de an\u00e1lisis DXF en Parodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018 Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018 y Autodesk Civil 3D 2018. Un archivo DXF especialmente creado puede desencadenar un use-after-free, lo que conlleva a la ejecuci\u00f3n del c\u00f3digo." } ], "id": "CVE-2019-7360", "lastModified": "2024-11-21T04:48:05.783", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2019-04-09T20:30:21.337", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 02:15
Modified
2025-05-06 19:51
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo MODEL creado con fines malintencionados, cuando se analiza en libodxdll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una doble liberaci\u00f3n. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23141", "lastModified": "2025-05-06T19:51:25.937", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T02:15:11.030", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-415" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-415" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 14:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPRODUCT manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de variable no inicializada. Un agente malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1650", "lastModified": "2025-08-19T14:15:36.793", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.990", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-908" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 04:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados en ASMKERN228A.dll o ASMDATAX228A.dll cuando se analiza mediante Autodesk AutoCAD podr\u00eda provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23131", "lastModified": "2025-04-11T15:56:25.960", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T04:15:08.797", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPRODUCT manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de variable no inicializada. Un agente malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1427", "lastModified": "2025-08-19T13:15:40.277", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:34.743", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-908" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:42
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPRODUCT creado con fines malintencionados, cuando se analiza en CC5Dll.dll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-37006", "lastModified": "2025-05-06T19:42:10.433", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:16.053", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2022-01-25 20:15
Modified
2024-11-21 06:23
Severity ?
Summary
A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-281/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-283/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-284/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-285/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-286/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-287/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-288/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-441/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-443/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-444/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-445/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-447/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-448/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-449/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-450/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-451/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-452/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-453/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-454/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-455/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-466/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-281/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-283/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-284/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-285/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-286/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-287/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-288/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-441/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-443/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-444/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-445/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-447/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-448/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-449/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-450/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-451/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-452/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-453/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-454/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-455/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-466/ | Third Party Advisory, VDB Entry |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | inventor | * | |
autodesk | inventor | 2019 | |
autodesk | inventor | 2020 | |
autodesk | inventor | 2021 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*", "matchCriteriaId": "D53B7E4C-4F2E-428D-A6CB-D4F2FB5865B0", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2019:*:*:*:*:*:*:*", "matchCriteriaId": "B0B62AB8-467B-4305-93C0-80F4ED72BFA0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2020:*:*:*:*:*:*:*", "matchCriteriaId": "521006E6-57DF-4E48-9D9B-70EED55DDC9D", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2021:*:*:*:*:*:*:*", "matchCriteriaId": "C14111CD-085E-4B05-8FB6-2B2F871BE963", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo JT malicioso en Autodesk Inventor 2022, 2021, 2020, 2019 y AutoCAD 2022 puede ser forzado a leer m\u00e1s all\u00e1 de los l\u00edmites asignados cuando se analiza el archivo JT. Esta vulnerabilidad, junto con otras, podr\u00eda conducir a la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual" } ], "id": "CVE-2021-40158", "lastModified": "2024-11-21T06:23:41.380", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-01-25T20:15:08.283", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-281/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-283/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-284/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-285/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-286/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-287/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-288/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-441/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-443/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-444/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-445/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-447/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-448/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-449/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-450/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-451/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-452/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-453/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-454/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-455/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-466/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-281/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-283/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-284/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-285/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-286/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-287/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-288/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-441/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-443/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-444/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-445/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-447/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-448/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-449/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-450/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-451/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-452/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-453/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-454/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-455/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-466/" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2019-04-09 20:30
Modified
2024-11-21 04:48
Severity ?
Summary
An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P&ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may cause a heap overflow, resulting in code execution.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2018 | |
autodesk | autocad | 2018 | |
autodesk | autocad_architecture | 2018 | |
autodesk | autocad_electrical | 2018 | |
autodesk | autocad_lt | 2018 | |
autodesk | autocad_map_3d | 2018 | |
autodesk | autocad_mechanical | 2018 | |
autodesk | autocad_mep | 2018 | |
autodesk | autocad_p\&id | 2018 | |
autodesk | autocad_plant_3d | 2018 | |
autodesk | civil_3d | 2018 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2018:*:*:*:*:*:*:*", "matchCriteriaId": "461B3C59-740C-4530-80DA-23DD38A0EEB7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2018:*:*:*:*:*:*:*", "matchCriteriaId": "4C2610D4-81E7-4B85-9147-C3F24895EDB0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2018:*:*:*:*:*:*:*", "matchCriteriaId": "ECDE64CF-3527-4C9A-9672-E2FA3BCC8B65", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "FC2B0DF8-8827-4CF2-94F1-D2871FA5095F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2018:*:*:*:*:*:*:*", "matchCriteriaId": "85BF0890-5AE7-46BA-8FD4-667B20081A0C", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "F4C4F749-A0C3-4C25-B5FC-CE3E49AFF8F6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "E34DF2FB-6A4F-4060-9DE4-EE635D9056E8", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2018:*:*:*:*:*:*:*", "matchCriteriaId": "BA943872-F736-4EC2-8328-9AABCAE08154", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_p\\\u0026id:2018:*:*:*:*:*:*:*", "matchCriteriaId": "B80C406D-9E82-4B2B-8065-FEB797DE65B1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "68F6B255-EE77-48BA-AEEE-9395C85BF274", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "2692C0E3-9A82-42BA-A80D-8A0D72FD3164", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P\u0026ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018, and Autodesk Civil 3D 2018. A specially crafted DXF file may cause a heap overflow, resulting in code execution." }, { "lang": "es", "value": "Se presenta una vulnerabilidad explotable de desbordamiento de pila en la funcionalidad DXF-parsing en Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk AutoCAD MEP 2018, Autodesk AutoCAD P \u0026 ID 2018, Autodesk AutoCAD Plant 3D 2018, Autodesk AutoCAD LT 2018 y Autodesk Civil 3D 2018. Un archivo DXF especialmente creado puede generar un desbordamiento de pila, lo que resulta en la ejecuci\u00f3n de c\u00f3digo malicioso." } ], "id": "CVE-2019-7358", "lastModified": "2024-11-21T04:48:05.523", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2019-04-09T20:30:21.227", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 15:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede generar una vulnerabilidad de uso despu\u00e9s de la liberaci\u00f3n. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1432", "lastModified": "2025-08-19T15:15:27.913", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.533", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:33
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.0 (High) - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.0 (High) - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM creado con fines malintencionados, cuando se analiza en opennurbs.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-36999", "lastModified": "2025-05-06T19:33:47.400", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.0, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.0, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:15.147", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 02:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL creado con fines malintencionados cuando se analiza en libodxdll.dll a trav\u00e9s de Autodesk AutoCAD puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23121", "lastModified": "2025-04-11T15:57:35.270", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T02:15:49.290", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo 3DM manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los l\u00edmites. Un agente malicioso podr\u00eda aprovechar esta vulnerabilidad para provocar un bloqueo, da\u00f1ar datos o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-7675", "lastModified": "2025-08-19T14:15:43.150", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:32.923", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-11 20:15
Modified
2024-11-21 06:53
Severity ?
Summary
A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | navisworks | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "395D75D7-FE8C-461D-8642-98BE81AA5277", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "B0E84020-F179-4AF3-BF9C-6D27259B2847", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87941CE7-7F89-4A09-BBE8-A0D829273A63", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F98B75B-1471-42A7-BCDA-95F7E65B7FD1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "C9338B09-BCD8-4E67-A331-1B8D5FB5DA24", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "86CF88E0-A49D-4528-8135-6BE5C9E5DD7C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "77A1562A-07B8-4130-B319-1BE2800D8771", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "0E59ACB5-8745-46A8-889E-005DEA38925B", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "CFFE146F-4AB2-45B2-9F87-52DD8DC26B85", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "230F8974-9613-4B58-8621-67CCE81E208C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF0FCE36-8A0F-4CDB-86B3-D8F7875511FD", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "1075AC6C-C9E1-45EA-B371-B06235C6AA86", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C71A1AD7-4651-4FA9-9114-023E07DCB285", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6929C4B1-27A0-4595-ABB6-48BB7F03A3EB", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "7AAFCE8D-C6FA-4179-BBD8-134F91261FEC", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code." }, { "lang": "es", "value": "Un archivo DXF dise\u00f1ado de forma maliciosa en Autodesk AutoCAD versiones 2022, 2021, 2020, 2019 y Autodesk Navisworks versi\u00f3n 2022, puede usarse para escribir m\u00e1s all\u00e1 del b\u00fafer asignado mediante Una vulnerabilidad de desbordamiento del b\u00fafer. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2022-25792", "lastModified": "2024-11-21T06:53:00.663", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-11T20:15:20.590", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los l\u00edmites. Un agente malicioso podr\u00eda aprovechar esta vulnerabilidad para provocar un bloqueo, da\u00f1ar datos o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-7497", "lastModified": "2025-08-19T14:15:42.883", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:32.733", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2021-06-25 13:15
Modified
2024-11-21 05:57
Severity ?
Summary
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-21-1236/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-21-1238/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-378/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-473/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-21-1236/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-21-1238/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-378/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-473/ | Third Party Advisory, VDB Entry |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | dwg_trueview | * | |
iconics | genesis64 | * | |
mitsubishielectric | mc_works64 | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "DDC0E547-C366-4A0E-95DE-EC420492E698", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B8319413-E093-4931-B2DB-A46522DF93C9", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B350B87-23EC-44F8-9A5F-9AC815E15BD9", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAE14E69-8BCB-4E00-8BAB-CB7F1688DC27", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A084A960-35D8-4B9C-87DE-0213CA40CAD8", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "20EE0BDC-3A97-4CD4-A232-922F8D613856", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "5FDD2042-5313-4658-AA4E-109684E91C43", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE031BD1-9F02-44C2-865E-2011511B36F5", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0A51CDDA-0D83-4331-9AB6-F6ED076157F6", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "143F8B16-E253-477E-9875-94928BE5596B", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "607A4804-A286-4237-82C3-8BE98662AE20", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "967B286E-5E73-47E3-BC2F-951E26720370", "versionEndIncluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "64C50E3E-8EFA-4B0D-B284-CF8FE4129866", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBD4F808-CA46-4A8E-82DD-6D1A82DDF91C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DFD09E68-2C34-4E76-9B67-868FA6E825A6", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "08BC587D-E4C7-4758-8AF5-1970892C35C8", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "282A07AC-8D43-4580-8D2E-8E30370049F3", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "E37E4967-AC88-42D6-98C2-1BA63F20BD5C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "49512EB3-DE17-45FF-AB90-2966462A9C3C", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "01A870BA-E78E-4975-BF6D-7D410BE8CD6C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EF85630-3DDC-4026-AC5A-F1B197F98C9E", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F5309100-B3E9-4144-AEA3-B9030E93FD78", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "954682D1-2E7A-4EAB-B4B8-43E2038EB7C7", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1016D7F3-2780-4412-A7AA-361B44A8632E", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A3D0B0D7-FC6F-43D8-85AA-AC0BD464E5A1", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF6DF983-6772-45D4-A82A-EE1BB2EEFD4F", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F7ABD866-E08B-42F3-A19A-5574563AA540", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6716F29E-FBA2-4178-A8AE-269D9CC5AC59", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "372905FF-2C9B-4366-BE56-36CACDA63BCD", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2F1DCEB-7ABB-4109-943A-E2DEFB17D330", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "EA49E2B8-CBF5-4F6E-A832-D1FDB597FADE", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8CF7601F-D6A3-4CD6-961D-B8B1B82E29CE", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5F285B8D-585C-4C23-98FA-E09DE53C8247", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A10D9CEE-D92D-470D-928F-8F90243618EE", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "0199953B-BCAC-405E-BDC6-951BEAE01570", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "FBDFDF50-5230-41F1-B380-AD3EC4B53DB7", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F6A3326B-382B-4137-B0E7-0D54E825B717", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "48F67A57-7528-406B-9BF1-6A963F732564", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "825FC323-CAE7-4B39-85AD-966980D30D89", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F430EA73-2B9F-42D9-9005-42F439ABF63C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "713BBAEC-BE6D-40BC-9FB3-EBB906FB09BA", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:iconics:genesis64:*:*:*:*:*:*:*:*", "matchCriteriaId": "EC66E916-D8A4-475B-A7E3-4E2FEF46A7B9", "versionEndIncluding": "10.97", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:mitsubishielectric:mc_works64:*:*:*:*:*:*:*:*", "matchCriteriaId": "AAE9E820-2348-4895-9F7D-96071747109D", "versionEndIncluding": "4.04e", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code." }, { "lang": "es", "value": "Un archivo DWG dise\u00f1ado maliciosamente puede ser forzado a leer m\u00e1s all\u00e1 de los l\u00edmites asignados al analizar el archivo DWG. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2021-27040", "lastModified": "2024-11-21T05:57:13.890", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 3.3, "baseSeverity": "LOW", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 1.4, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-06-25T13:15:08.187", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1236/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1238/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-378/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-473/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1236/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-1238/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-378/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-473/" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-11 20:15
Modified
2024-11-21 06:53
Severity ?
Summary
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | navisworks | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "395D75D7-FE8C-461D-8642-98BE81AA5277", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "B0E84020-F179-4AF3-BF9C-6D27259B2847", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87941CE7-7F89-4A09-BBE8-A0D829273A63", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F98B75B-1471-42A7-BCDA-95F7E65B7FD1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "C9338B09-BCD8-4E67-A331-1B8D5FB5DA24", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "86CF88E0-A49D-4528-8135-6BE5C9E5DD7C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "77A1562A-07B8-4130-B319-1BE2800D8771", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "0E59ACB5-8745-46A8-889E-005DEA38925B", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "CFFE146F-4AB2-45B2-9F87-52DD8DC26B85", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "230F8974-9613-4B58-8621-67CCE81E208C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF0FCE36-8A0F-4CDB-86B3-D8F7875511FD", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "1075AC6C-C9E1-45EA-B371-B06235C6AA86", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C71A1AD7-4651-4FA9-9114-023E07DCB285", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6929C4B1-27A0-4595-ABB6-48BB7F03A3EB", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "7AAFCE8D-C6FA-4179-BBD8-134F91261FEC", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution." }, { "lang": "es", "value": "Un archivo DWF maliciosamente dise\u00f1ado en Autodesk AutoCAD versiones 2022, 2021, 2020, 2019 y Autodesk Navisworks versi\u00f3n 2022 puede usarse para escribir m\u00e1s all\u00e1 de los l\u00edmites asignados cuando son analizados los archivos DWF. Una explotaci\u00f3n de esta vulnerabilidad puede conllevar a una ejecuci\u00f3n de c\u00f3digo" } ], "id": "CVE-2022-25790", "lastModified": "2024-11-21T06:53:00.433", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-11T20:15:20.503", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:43
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
4.2 (Medium) - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
4.2 (Medium) - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
Summary
A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo IGES creado con fines malintencionados, cuando se analiza en ASMImport229A.dll a trav\u00e9s de aplicaciones de Autodesk, puede usarse para provocar una vulnerabilidad de use-after-free. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23158", "lastModified": "2025-05-06T19:43:45.167", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.2, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 2.5, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:14.007", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-416" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:48
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
6.3 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
6.3 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Summary
A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo SLDPRT creado con fines malintencionados, cuando se analiza en ODXSW_DLL.dll a trav\u00e9s de aplicaciones de Autodesk, se puede utilizar para provocar un desbordamiento basado en mont\u00f3n. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23154", "lastModified": "2025-05-06T19:48:16.993", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 6.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 3.4, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:13.153", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-11 20:15
Modified
2024-11-21 06:53
Severity ?
Summary
A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | navisworks | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "395D75D7-FE8C-461D-8642-98BE81AA5277", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "B0E84020-F179-4AF3-BF9C-6D27259B2847", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87941CE7-7F89-4A09-BBE8-A0D829273A63", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F98B75B-1471-42A7-BCDA-95F7E65B7FD1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "C9338B09-BCD8-4E67-A331-1B8D5FB5DA24", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "86CF88E0-A49D-4528-8135-6BE5C9E5DD7C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "77A1562A-07B8-4130-B319-1BE2800D8771", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "0E59ACB5-8745-46A8-889E-005DEA38925B", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "CFFE146F-4AB2-45B2-9F87-52DD8DC26B85", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "230F8974-9613-4B58-8621-67CCE81E208C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF0FCE36-8A0F-4CDB-86B3-D8F7875511FD", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "1075AC6C-C9E1-45EA-B371-B06235C6AA86", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C71A1AD7-4651-4FA9-9114-023E07DCB285", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6929C4B1-27A0-4595-ABB6-48BB7F03A3EB", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*", "matchCriteriaId": "7AAFCE8D-C6FA-4179-BBD8-134F91261FEC", "versionEndExcluding": "2022.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files." }, { "lang": "es", "value": "Una vulnerabilidad de Corrupci\u00f3n de Memoria para archivos DWF y DWFX en Autodesk AutoCAD versiones 2022, 2021, 2020, 2019 y Autodesk Navisworks versi\u00f3n 2022, puede conllevar a una ejecuci\u00f3n de c\u00f3digo mediante archivos DLL maliciosamente dise\u00f1ados" } ], "id": "CVE-2022-25791", "lastModified": "2024-11-21T06:53:00.550", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.4, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 3.4, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-11T20:15:20.547", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0005" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 04:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados en ASMDATAX228A.dll cuando se analiza mediante Autodesk AutoCAD podr\u00eda provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23133", "lastModified": "2025-04-11T15:56:10.517", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T04:15:08.917", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-04-15 21:15
Modified
2025-08-19 13:15
Severity ?
Summary
A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * | |
autodesk | dwg_trueview | * | |
autodesk | infrastructure_parts_editor | * | |
autodesk | infrastructure_parts_editor | * | |
autodesk | inventor | * | |
autodesk | inventor | * | |
autodesk | navisworks_manage | * | |
autodesk | navisworks_manage | * | |
autodesk | navisworks_simulate | * | |
autodesk | navisworks_simulate | * | |
autodesk | revit | * | |
autodesk | revit | * | |
autodesk | vault | * | |
autodesk | vault | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "BAA7DE4E-9D9D-4A3C-9813-1ECA420CA55D", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "973B1CE6-8763-42F4-9E43-46CA1C0398FE", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "6DF31D4A-4E66-4425-98C3-3A4172F27634", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "3B8C034F-57BD-4F6D-B6F0-904FC1212CBB", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "5A34FC4A-17E3-4F32-AF55-146A3E0A8D73", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "DACE53EA-C06D-4BAD-A47C-2AD7D9BA3FC7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "CB3814C7-89F1-4769-A667-8A941FECFECA", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "B5615AA3-02AB-41E6-B207-C8E2BF14381B", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "68D32CA8-DAE5-454E-9611-6DC7D39936B6", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*", "matchCriteriaId": "9ACA58FE-046E-47D0-B091-58725ABC1D5E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*", "matchCriteriaId": "06EEA81D-D2D2-4553-8B50-7CF851D2F451", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*", "matchCriteriaId": "AA2D3721-3DFB-4BF2-AB50-F7FB5D582DFB", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*", "matchCriteriaId": "33271DFE-EA9E-470B-889C-920D7CC014D9", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C24857A-342D-4B37-89D7-BAD0C71D58F1", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*", "matchCriteriaId": "E3B7FDC4-BEC1-4F90-A112-6960176F6748", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*", "matchCriteriaId": "28734A5D-CAEB-4F94-9892-DA3F45E3DA41", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B72D634-D894-406F-81F0-2421BA22FFAD", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "328F43A7-346C-4C9D-8153-74497327D053", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*", "matchCriteriaId": "9C38D944-8471-47A0-AFAC-ECA76CB58E57", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6486EE-BCC7-469A-B5B7-B9950B1DEF67", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*", "matchCriteriaId": "611BC4BF-41BF-46D9-ADB2-92B6CBAB9FBE", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DWG manipulado con fines maliciosos, al analizarse mediante ciertas aplicaciones de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los l\u00edmites. Un agente malicioso podr\u00eda aprovechar esta vulnerabilidad para provocar un bloqueo, da\u00f1ar datos o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1276", "lastModified": "2025-08-19T13:15:39.800", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-04-15T21:15:47.320", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/dwg-trueview/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de lectura fuera de los l\u00edmites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1433", "lastModified": "2025-08-19T13:15:41.223", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.683", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-08-15 15:15
Modified
2025-08-20 21:22
Severity ?
Summary
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_lt | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*", "matchCriteriaId": "51F919FB-6AFC-43FF-91C4-DC15FCF5B6EF", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo DGN manipulado con fines maliciosos, al vincularse o importarse a Autodesk AutoCAD, puede generar una vulnerabilidad de corrupci\u00f3n de memoria. Un agente malicioso puede aprovechar esta vulnerabilidad para ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-5048", "lastModified": "2025-08-20T21:22:13.190", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Primary" } ] }, "published": "2025-08-15T15:15:33.327", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Product" ], "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-120" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2022-01-25 20:15
Modified
2024-11-21 06:23
Severity ?
Summary
An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-282/ | Third Party Advisory, VDB Entry | |
psirt@autodesk.com | https://www.zerodayinitiative.com/advisories/ZDI-22-289/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-282/ | Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.zerodayinitiative.com/advisories/ZDI-22-289/ | Third Party Advisory, VDB Entry |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | inventor | 2019 | |
autodesk | inventor | 2020 | |
autodesk | inventor | 2021 | |
autodesk | inventor | 2022 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5F50DF-4792-4A29-BB21-5821CA5E3A22", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "D01E3771-86FD-483D-BCCB-1B1CDD4C482F", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2019:*:*:*:*:*:*:*", "matchCriteriaId": "B0B62AB8-467B-4305-93C0-80F4ED72BFA0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2020:*:*:*:*:*:*:*", "matchCriteriaId": "521006E6-57DF-4E48-9D9B-70EED55DDC9D", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2021:*:*:*:*:*:*:*", "matchCriteriaId": "C14111CD-085E-4B05-8FB6-2B2F871BE963", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:inventor:2022:*:*:*:*:*:*:*", "matchCriteriaId": "C67079A0-1C2B-45F9-91CC-74C685D31B67", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process." }, { "lang": "es", "value": "Una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n para archivos JT en Autodesk Inventor 2022, 2021, 2020, 2019 junto con otras vulnerabilidades puede conducir a la ejecuci\u00f3n de c\u00f3digo a trav\u00e9s de archivos JT maliciosamente elaborados en el contexto del proceso actual" } ], "id": "CVE-2021-40159", "lastModified": "2024-11-21T06:23:41.587", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-01-25T20:15:08.327", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-282/" }, { "source": "psirt@autodesk.com", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-289/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-282/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-289/" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-200" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 03:15
Modified
2025-05-06 19:45
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo MODEL creado con fines malintencionados, cuando se analiza en ASMkern229A.dll a trav\u00e9s de aplicaciones de Autodesk, se puede utilizar para variables no inicializadas. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-37002", "lastModified": "2025-05-06T19:45:30.817", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T03:15:10.647", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-457" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-863" } ], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 02:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPART creado con fines malintencionados, cuando se analiza en CC5Dll.dll y ASMBASE228A.dll a trav\u00e9s de Autodesk AutoCAD, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23123", "lastModified": "2025-04-11T15:57:23.400", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T02:15:49.433", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2022-04-18 17:15
Modified
2024-11-21 06:55
Severity ?
Summary
A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "395D75D7-FE8C-461D-8642-98BE81AA5277", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "525AD44E-386E-42C9-8B2E-90F29855DF4A", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "7CDC63B1-6EA4-48C6-998A-A86A82A74BD4", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E1BE9431-DC86-4ABB-8EE2-9FADA3B0AEBA", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "41A08A1E-5CC8-4F1A-8485-871366315BAC", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "A8B6181F-DFD8-4105-B277-95729F8EF34F", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "B234B44D-C528-4213-AE32-DEED2EC472F1", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*", "matchCriteriaId": "E3116E10-FB93-4EC7-957E-B130FE5153BF", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:*", "matchCriteriaId": "8357611C-929E-407C-B4C8-6ED926E513C6", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "C9338B09-BCD8-4E67-A331-1B8D5FB5DA24", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "F616B84F-B471-43B9-BC5D-BA6CCE461F56", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "AD0B37E9-4987-4B96-9B31-6168961E1496", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E9466EE6-83C9-492F-8486-F3E6C1DD9F5A", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "86CF88E0-A49D-4528-8135-6BE5C9E5DD7C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E716111F-273B-48DF-ADEA-44BADE5E7FEB", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "71FA0271-BE55-48AD-B88D-34645684E9DE", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6DD91E39-A3D8-4806-A778-608FD6C29BB2", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "04AF77FA-C980-47ED-B4C5-EEA965D425DF", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "F5783F63-D6BF-44BB-8001-3134D4CD5CF0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "3E1AB702-ABBD-4110-9B27-F4C2EC3F6A00", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*", "matchCriteriaId": "0DC17B10-E6E8-4D49-BDEF-DBC5097580C9", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:*", "matchCriteriaId": "EEC464C9-D741-41B4-B460-B4305BCD83FA", "versionEndExcluding": "2022.2.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "230F8974-9613-4B58-8621-67CCE81E208C", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "D9184783-2476-4ED0-9F05-CA2AC68446B3", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "752B8F1C-54E3-4985-97A4-86FBF13E6BFD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "120326C3-E212-4341-A25D-BC3DD50CF228", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF0FCE36-8A0F-4CDB-86B3-D8F7875511FD", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5BAA6D71-2B11-4490-A1C4-652347582EF6", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6F78C528-605C-46F3-8CF0-828B682745B3", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B117299A-C5FE-419F-9C1C-DF58A2772055", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "1075AC6C-C9E1-45EA-B371-B06235C6AA86", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBC04C9D-9E69-4CB7-BF7A-D3B8C0670114", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E140DC9-7000-48ED-A5C7-B23023DFB199", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CC178212-E440-46E9-9F00-60A5516D4D72", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C71A1AD7-4651-4FA9-9114-023E07DCB285", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C2A2E5FC-9717-47C1-A223-F90DC572DAB0", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "984491F0-8303-4C6C-B884-00C032D797DD", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7ED0DB1D-6F37-4C1B-B55E-42F3A4E34299", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6929C4B1-27A0-4595-ABB6-48BB7F03A3EB", "versionEndExcluding": "2019.1.4", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EE4E278B-360E-4F00-8479-9531EB417269", "versionEndExcluding": "2020.1.5", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "577AEF72-23CC-45D9-B391-8A3D79DAB5BA", "versionEndExcluding": "2021.1.2", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "82C21398-6A86-4E56-A98E-E80FFCC6732E", "versionEndExcluding": "2022.1.2", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code." }, { "lang": "es", "value": "Un archivo TIF o PICT dise\u00f1ado de forma maliciosa en Autodesk AutoCAD versiones 2022, 2021, 2020, 2019, puede usarse para escribir m\u00e1s all\u00e1 del b\u00fafer asignado mediante una vulnerabilidad de desbordamiento del B\u00fafer. Esta vulnerabilidad puede ser explotada para ejecutar c\u00f3digo arbitrario" } ], "id": "CVE-2022-27530", "lastModified": "2024-11-21T06:55:53.470", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2022-04-18T17:15:16.937", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede generar una vulnerabilidad de desbordamiento basado en mont\u00f3n. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1429", "lastModified": "2025-08-19T13:15:40.683", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:35.053", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 02:15
Modified
2025-05-06 19:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A59E87D5-A95F-4609-937F-96216FD82EE1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "554F1A83-6B21-49D1-A0DC-EADA868F70EF", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B2BB68E0-BC12-4146-B54E-A05CEEC52AAA", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "47C0F26A-B876-46EA-A347-78C624500734", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9785E046-9BD6-4368-B53B-52E43E926DC4", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "9BD4B27F-C997-4CEE-8186-B5B3389BCF8B", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1B22B643-421A-4A5B-BD20-9C2F85AAE1D1", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "77AD92A5-0772-46EB-9133-D93B5250B23A", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FFEE1D1-2B84-45E8-AF0C-37C056ECABC2", "versionEndExcluding": "2024.1.4", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPART creado con fines malintencionados, cuando se analiza en CC5Dll.dll y ASMBASE228A.dll mediante aplicaciones de Autodesk, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23144", "lastModified": "2025-05-06T19:56:18.307", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T02:15:11.293", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2021-06-25 13:15
Modified
2024-11-21 05:57
Severity ?
Summary
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_lt | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | dwg_trueview | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "DDC0E547-C366-4A0E-95DE-EC420492E698", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B8319413-E093-4931-B2DB-A46522DF93C9", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B350B87-23EC-44F8-9A5F-9AC815E15BD9", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAE14E69-8BCB-4E00-8BAB-CB7F1688DC27", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "A084A960-35D8-4B9C-87DE-0213CA40CAD8", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "20EE0BDC-3A97-4CD4-A232-922F8D613856", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "5FDD2042-5313-4658-AA4E-109684E91C43", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE031BD1-9F02-44C2-865E-2011511B36F5", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0A51CDDA-0D83-4331-9AB6-F6ED076157F6", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "143F8B16-E253-477E-9875-94928BE5596B", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "607A4804-A286-4237-82C3-8BE98662AE20", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "967B286E-5E73-47E3-BC2F-951E26720370", "versionEndIncluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "64C50E3E-8EFA-4B0D-B284-CF8FE4129866", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CBD4F808-CA46-4A8E-82DD-6D1A82DDF91C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DFD09E68-2C34-4E76-9B67-868FA6E825A6", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "08BC587D-E4C7-4758-8AF5-1970892C35C8", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "282A07AC-8D43-4580-8D2E-8E30370049F3", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "E37E4967-AC88-42D6-98C2-1BA63F20BD5C", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "49512EB3-DE17-45FF-AB90-2966462A9C3C", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*", "matchCriteriaId": "01A870BA-E78E-4975-BF6D-7D410BE8CD6C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EF85630-3DDC-4026-AC5A-F1B197F98C9E", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F5309100-B3E9-4144-AEA3-B9030E93FD78", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "954682D1-2E7A-4EAB-B4B8-43E2038EB7C7", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "1016D7F3-2780-4412-A7AA-361B44A8632E", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A3D0B0D7-FC6F-43D8-85AA-AC0BD464E5A1", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "AF6DF983-6772-45D4-A82A-EE1BB2EEFD4F", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F7ABD866-E08B-42F3-A19A-5574563AA540", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "6716F29E-FBA2-4178-A8AE-269D9CC5AC59", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "372905FF-2C9B-4366-BE56-36CACDA63BCD", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2F1DCEB-7ABB-4109-943A-E2DEFB17D330", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "EA49E2B8-CBF5-4F6E-A832-D1FDB597FADE", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "8CF7601F-D6A3-4CD6-961D-B8B1B82E29CE", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5F285B8D-585C-4C23-98FA-E09DE53C8247", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A10D9CEE-D92D-470D-928F-8F90243618EE", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "0199953B-BCAC-405E-BDC6-951BEAE01570", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "FBDFDF50-5230-41F1-B380-AD3EC4B53DB7", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F6A3326B-382B-4137-B0E7-0D54E825B717", "versionEndExcluding": "2019.1.3", "versionStartIncluding": "2019", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "48F67A57-7528-406B-9BF1-6A963F732564", "versionEndExcluding": "2020.1.4", "versionStartIncluding": "2020", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "825FC323-CAE7-4B39-85AD-966980D30D89", "versionEndExcluding": "2021.1.1", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F430EA73-2B9F-42D9-9005-42F439ABF63C", "versionEndExcluding": "2022.0.1", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*", "matchCriteriaId": "713BBAEC-BE6D-40BC-9FB3-EBB906FB09BA", "versionEndExcluding": "2022.1.1", "versionStartIncluding": "2022", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application." }, { "lang": "es", "value": "Un problema de escritura de direcciones arbitrarias en la aplicaci\u00f3n Autodesk DWG, puede permitir a un usuario malicioso aprovechar la aplicaci\u00f3n para escribir en rutas inesperadas. Para explotar esto, el atacante necesitar\u00eda que la v\u00edctima habilitara la pila de p\u00e1gina completa en la aplicaci\u00f3n" } ], "id": "CVE-2021-27043", "lastModified": "2024-11-21T05:57:14.307", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2021-06-25T13:15:08.280", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0007" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-07-29 18:15
Modified
2025-08-19 14:15
Severity ?
Summary
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | shared_components | 2026.2 | |
autodesk | 3ds_max | 2026 | |
autodesk | advance_steel | 2026 | |
autodesk | autocad | 2026 | |
autodesk | autocad_architecture | 2026 | |
autodesk | autocad_electrical | 2026 | |
autodesk | autocad_map_3d | 2026 | |
autodesk | autocad_mechanical | 2026 | |
autodesk | autocad_mep | 2026 | |
autodesk | autocad_plant_3d | 2026 | |
autodesk | civil_3d | 2026 | |
autodesk | infraworks | 2026 | |
autodesk | inventor | 2026 | |
autodesk | revit | 2026 | |
autodesk | revit_lt | 2026 | |
autodesk | vault | 2026 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*", "matchCriteriaId": "F619380D-7F2A-453B-BC9C-EBF82B7628A7", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*", "matchCriteriaId": "B938D507-D95A-4EAD-86AB-9B52A3682414", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*", "matchCriteriaId": "68738B5A-B918-4CA3-BD13-4040B3219AFC", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*", "matchCriteriaId": "8890EECB-7AB5-41A3-8E77-314183BC3AB3", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*", "matchCriteriaId": "CE935915-6926-474F-B5A4-7E77EF7426DD", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "BEC23105-1362-4BFE-9C93-F0AAA5BAF2B0", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "2DB79016-0BB6-4E8A-8AE3-5AB39A252DED", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*", "matchCriteriaId": "4A159D88-990D-41D7-B6B0-D97B38241860", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*", "matchCriteriaId": "046ADE16-4275-4BEF-9A71-480E709383F7", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "EEB9FCDC-6717-44EB-AA55-983A771E2460", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*", "matchCriteriaId": "3383C40E-DD43-4146-9B58-C44585E40985", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*", "matchCriteriaId": "1B01CD79-B993-47BB-B775-C10422FB956B", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*", "matchCriteriaId": "F7393B89-15A9-4709-9FF3-DA1C88770594", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*", "matchCriteriaId": "58A56B67-B754-4525-995A-F70CAA6B5AAB", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*", "matchCriteriaId": "DF3C0C68-F0D7-4737-8D37-D99F128DAB47", "vulnerable": false }, { "criteria": "cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*", "matchCriteriaId": "08F81FC1-1B7C-40AF-88DB-B62F24CFA21C", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los l\u00edmites. Un agente malicioso podr\u00eda aprovechar esta vulnerabilidad para provocar un bloqueo, da\u00f1ar datos o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-6637", "lastModified": "2025-08-19T14:15:42.677", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" } ] }, "published": "2025-07-29T18:15:32.550", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 03:15
Modified
2025-04-11 15:57
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados cuando se analiza en ASMIMPORT228A.dll a trav\u00e9s de Autodesk AutoCAD puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23124", "lastModified": "2025-04-11T15:57:18.310", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T03:15:08.027", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 04:15
Modified
2025-04-11 15:56
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados en atf_dwg_consumer.dll cuando se analiza mediante Autodesk AutoCAD podr\u00eda provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual." } ], "id": "CVE-2024-23132", "lastModified": "2025-04-11T15:56:16.183", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T04:15:08.857", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:43
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo 3DM creado con fines malintencionados, cuando se analiza en opennurbs.dll y ASMkern229A.dll a trav\u00e9s de aplicaciones de Autodesk, puede provocar una vulnerabilidad de corrupci\u00f3n de memoria por infracci\u00f3n de acceso de escritura. Esta vulnerabilidad, junto con otras vulnerabilidades, puede provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23156", "lastModified": "2025-05-06T19:43:16.420", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:13.450", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-119" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-02-22 05:15
Modified
2025-04-11 15:55
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5 (High) - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5833D3EE-E6F2-4F72-B66A-D1441E3A4F32", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0EC7C7DA-1682-43FF-8515-2C5E6C9CC502", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A71C7E76-81BB-40C7-AE45-65E26651FA04", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "B77DFA45-167C-453A-A543-16A4A51514B4", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "2EAD1ED0-0761-49CA-BAF0-2A4EB39FEEFD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "770B3D64-582F-453E-A8CD-D2B655EEA3DF", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "C12DA888-C72E-424A-9A66-2B72C3885022", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CDA5C264-8E3E-4EB3-A586-BAF5076F9B5F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "A7019B5E-D425-41CC-9F35-D4A92597BA6A", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0BECC47B-077B-4448-AB37-FDA334A1CDA9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "A16CEB16-2B44-4AF2-A0F4-497F30DC70CC", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "4BDB09F0-77AB-4177-9059-F67A7D2781A2", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "94B704A0-03BB-4F75-8621-142FC2EB3F3F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF2BDC5F-7710-4C2A-AF60-71F3A1E4B020", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "15E49672-CBD2-4052-AC01-F0B02AF94AAF", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CEFE632B-569A-433B-96C1-FF87BD35F168", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "93561E79-EBDF-4DE1-92F8-CF5764932523", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "798D132D-E71C-4C94-A2A4-B5ED222FE2A0", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4C1FC811-08B1-4C9D-B65D-7BACAC04A72C", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F745DE13-EA25-48E7-9DC0-8A11051D3DB1", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "57C7AA10-6C8D-4CD7-8BBE-1B7069F9DC48", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5068B231-93C3-4CAF-A679-A87117016472", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "C5622C87-4585-4EBD-A868-95DF104C6B8F", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "B1930F6C-449E-481A-8E7E-48CF14FF4310", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F954159B-F922-4D0D-826D-A5390C94DFA2", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "70BC67D3-9BB7-4882-ACF7-3866AB487555", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "1FF491D7-280B-4DEE-B912-8677F62D3195", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "B09BA7FD-4C04-4B7A-9824-19F918651A5B", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "4B55C95F-762E-4356-9A5C-83CFFC99A743", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "01723BB3-1692-41D5-9123-5FB17F8C44AD", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7169F2CB-58BB-46C2-883D-4FE3E66A4940", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "4540CC32-0DDA-4483-A087-D95C3C610287", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "EB7AE2EA-96D5-47AE-A667-AFD5F57047B4", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7E44032A-F590-43E0-92DF-5FD3E142E147", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "407362FB-1FC4-4B78-843B-C64539AEE7F9", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "87CE995F-0A26-4A6B-ADAD-BD92DE041CC0", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE884173-F3DD-499F-BD76-30163694A4C8", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F731E320-ECF2-4475-A272-1F5001F69F6C", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "6E84F5F3-11EC-4F50-A876-82A3711B2887", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "D2E7315F-F000-4259-9B22-19155ECFF63C", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "3ECBFF29-3DF6-486F-AD72-96D27CC606CA", "versionEndExcluding": "2021.1.4", "versionStartIncluding": "2021", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "E605F3C7-2CE6-47D2-9FD9-894F2DA6653B", "versionEndExcluding": "2022.1.4", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6B0C6F22-AD34-47F3-BD17-44BDDBD1DF54", "versionEndExcluding": "2023.1.5", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "806EBADF-277C-45C8-95C8-9DDDC3A587F2", "versionEndExcluding": "2024.1.3", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "84FA9407-98AC-4ABC-B406-76A9D324C070", "versionEndExcluding": "2025.0.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process." }, { "lang": "es", "value": "Un archivo STP creado con fines malintencionados cuando ASMKERN228A.dll se analiza mediante Autodesk AutoCAD se puede utilizar para eliminar la referencia a un puntero que no es de confianza. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el proceso actual." } ], "id": "CVE-2024-23136", "lastModified": "2025-04-11T15:55:48.427", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.6, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-02-22T05:15:09.527", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-822" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 14:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo MODEL manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede generar una vulnerabilidad de desbordamiento basado en mont\u00f3n. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1651", "lastModified": "2025-08-19T14:15:36.970", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:36.153", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-122" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2019-08-23 20:15
Modified
2024-11-21 04:48
Severity ?
Summary
DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002 | Patch, Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002 | Patch, Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | advance_steel | 2017 | |
autodesk | advance_steel | 2018 | |
autodesk | advance_steel | 2019 | |
autodesk | advance_steel | 2020 | |
autodesk | autocad | 2017 | |
autodesk | autocad | 2018 | |
autodesk | autocad | 2019 | |
autodesk | autocad | 2020 | |
autodesk | autocad_architecture | 2017 | |
autodesk | autocad_architecture | 2018 | |
autodesk | autocad_architecture | 2019 | |
autodesk | autocad_architecture | 2020 | |
autodesk | autocad_electrical | 2017 | |
autodesk | autocad_electrical | 2018 | |
autodesk | autocad_electrical | 2019 | |
autodesk | autocad_electrical | 2020 | |
autodesk | autocad_lt | 2017 | |
autodesk | autocad_lt | 2018 | |
autodesk | autocad_lt | 2019 | |
autodesk | autocad_lt | 2020 | |
autodesk | autocad_map_3d | 2017 | |
autodesk | autocad_map_3d | 2018 | |
autodesk | autocad_map_3d | 2019 | |
autodesk | autocad_map_3d | 2020 | |
autodesk | autocad_mechanical | 2017 | |
autodesk | autocad_mechanical | 2018 | |
autodesk | autocad_mechanical | 2019 | |
autodesk | autocad_mechanical | 2020 | |
autodesk | autocad_mep | 2017 | |
autodesk | autocad_mep | 2018 | |
autodesk | autocad_mep | 2019 | |
autodesk | autocad_mep | 2020 | |
autodesk | autocad_p\&id | 2017 | |
autodesk | autocad_plant_3d | 2017 | |
autodesk | autocad_plant_3d | 2018 | |
autodesk | autocad_plant_3d | 2019 | |
autodesk | autocad_plant_3d | 2020 | |
autodesk | civil_3d | 2017 | |
autodesk | civil_3d | 2018 | |
autodesk | civil_3d | 2019 | |
autodesk | civil_3d | 2020 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:2017:*:*:*:*:*:*:*", "matchCriteriaId": "CB72BEDD-3A76-44B8-8192-D4F12C87488D", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2018:*:*:*:*:*:*:*", "matchCriteriaId": "461B3C59-740C-4530-80DA-23DD38A0EEB7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2019:*:*:*:*:*:*:*", "matchCriteriaId": "963B02A8-97DE-4C10-9AE1-3DA4FBC9AF9F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:2020:*:*:*:*:*:*:*", "matchCriteriaId": "8C4543D1-94E4-4470-91BF-6F3141FD9DAE", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2017:*:*:*:*:*:*:*", "matchCriteriaId": "D45E4513-4F91-492F-ABFA-E67EAEB3514C", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2018:*:*:*:*:*:*:*", "matchCriteriaId": "4C2610D4-81E7-4B85-9147-C3F24895EDB0", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2019:*:*:*:*:*:*:*", "matchCriteriaId": "411DC826-735A-4BEB-84BE-9250F97F612E", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:2020:*:*:*:*:*:*:*", "matchCriteriaId": "E30E2562-D38E-4764-874E-5B2FCF5639E5", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2017:*:*:*:*:*:*:*", "matchCriteriaId": "65CA52C5-9F62-455C-949C-4AE00FDDFA09", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2018:*:*:*:*:*:*:*", "matchCriteriaId": "ECDE64CF-3527-4C9A-9672-E2FA3BCC8B65", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2019:*:*:*:*:*:*:*", "matchCriteriaId": "9275E76C-2A79-462A-A9D3-D0B6BBCDD0CC", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:2020:*:*:*:*:*:*:*", "matchCriteriaId": "B7DFA12E-48C5-47B9-BD9F-1AFACBF4E1EA", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2017:*:*:*:*:*:*:*", "matchCriteriaId": "D93A0DCA-DE9C-4A0E-8EC3-46B1B32D88EB", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "FC2B0DF8-8827-4CF2-94F1-D2871FA5095F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2019:*:*:*:*:*:*:*", "matchCriteriaId": "A10DE5AF-1718-4899-9238-CFFDC72D05B7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:2020:*:*:*:*:*:*:*", "matchCriteriaId": "E388264D-D2D4-4BE4-9097-8F547D73ABE5", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2017:*:*:*:*:*:*:*", "matchCriteriaId": "36D3F11C-900E-436C-A628-75CE5218489B", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2018:*:*:*:*:*:*:*", "matchCriteriaId": "85BF0890-5AE7-46BA-8FD4-667B20081A0C", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2019:*:*:*:*:*:*:*", "matchCriteriaId": "03682B7E-1CF1-4456-A51F-A6ADFC177935", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_lt:2020:*:*:*:*:*:*:*", "matchCriteriaId": "371C5F60-4959-40C7-93E1-A01510A95115", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2017:*:*:*:*:*:*:*", "matchCriteriaId": "7773B26C-12D3-4D00-990D-16F6978302A7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "F4C4F749-A0C3-4C25-B5FC-CE3E49AFF8F6", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2019:*:*:*:*:*:*:*", "matchCriteriaId": "04E05510-B21B-4DDD-88D7-CEB8963E1AFB", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:2020:*:*:*:*:*:*:*", "matchCriteriaId": "D4CD010A-FDBC-40F9-95AC-0CD8388B85D1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2017:*:*:*:*:*:*:*", "matchCriteriaId": "A591011C-4E67-497D-89B4-6F32460EEF1F", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2018:*:*:*:*:*:*:*", "matchCriteriaId": "E34DF2FB-6A4F-4060-9DE4-EE635D9056E8", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2019:*:*:*:*:*:*:*", "matchCriteriaId": "19255CEC-6161-4D44-B87E-52E86DF4FBA7", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:2020:*:*:*:*:*:*:*", "matchCriteriaId": "7147F378-DFB0-48A8-8B05-8777E1CC7F90", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2017:*:*:*:*:*:*:*", "matchCriteriaId": "01D7FD7C-B818-4FA1-A845-6721729274EA", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2018:*:*:*:*:*:*:*", "matchCriteriaId": "BA943872-F736-4EC2-8328-9AABCAE08154", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2019:*:*:*:*:*:*:*", "matchCriteriaId": "3F608B1C-BA96-4EA8-A540-83870262CBC1", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:2020:*:*:*:*:*:*:*", "matchCriteriaId": "7CFAAD19-6248-42CB-B177-EC2E5141A953", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_p\\\u0026id:2017:*:*:*:*:*:*:*", "matchCriteriaId": "166A2A40-5073-4072-BBF9-5593FA052680", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2017:*:*:*:*:*:*:*", "matchCriteriaId": "15F0D764-62D6-4729-BB98-8C4BEBACD45A", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "68F6B255-EE77-48BA-AEEE-9395C85BF274", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2019:*:*:*:*:*:*:*", "matchCriteriaId": "4E536B0D-4C95-4589-981A-2F8A6C4B44DC", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:2020:*:*:*:*:*:*:*", "matchCriteriaId": "3FBDD3AC-FA00-462F-AA13-5A75B5D50689", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2017:*:*:*:*:*:*:*", "matchCriteriaId": "6AAAC86E-4D30-4A33-AC84-57486A7C26D8", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2018:*:*:*:*:*:*:*", "matchCriteriaId": "2692C0E3-9A82-42BA-A80D-8A0D72FD3164", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2019:*:*:*:*:*:*:*", "matchCriteriaId": "7F8A4F1F-0D78-41FB-BB62-4A6164AC0F51", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:2020:*:*:*:*:*:*:*", "matchCriteriaId": "F2A4C41C-E547-4693-8C53-E21A56323D52", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P\u0026ID. An attacker may trick a user into opening a malicious DWG file that may leverage a DLL preloading vulnerability in AutoCAD which may result in code execution." }, { "lang": "es", "value": "Vulnerabilidad de precarga de DLL en las versiones 2017, 2018, 2019 y 2020 de Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D y la versi\u00f3n 2017 de AutoCAD P\u0026ID. Un atacante puede enga\u00f1ar a un usuario para que abra un archivo DWG malicioso que puede aprovechar una vulnerabilidad de precarga de DLL en AutoCAD que puede provocar la ejecuci\u00f3n del c\u00f3digo." } ], "id": "CVE-2019-7364", "lastModified": "2024-11-21T04:48:06.343", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 6.8, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2019-08-23T20:15:10.690", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Patch", "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2019-0002" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-427" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2025-03-13 17:15
Modified
2025-08-19 13:15
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
▶ | URL | Tags | |
---|---|---|---|
psirt@autodesk.com | https://www.autodesk.com/products/autodesk-access/overview | ||
psirt@autodesk.com | https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html | ||
psirt@autodesk.com | https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001 | Vendor Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2C955BA-BB73-4A97-8027-B67129D4426B", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "8E9C42B7-DD9F-4881-B7D4-13022C4FE39F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "4D60421A-C46E-4C42-B675-F235BC21BA87", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF19943B-FEE9-460C-AEA5-A402717D202E", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "4F6F8968-9757-47B1-894C-212C17380B0A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "2C5628D4-B66A-4D97-A079-0288AB4A78D1", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "7063D783-E671-421A-99D2-AC6DFAAA298C", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "0DDEB087-1A78-402D-A50F-64A172B941D3", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "E70F365A-24CA-4EB7-9C2C-D984269E45AD", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3D6F5A94-EE54-43B3-955F-7C3615D6E0E0", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "3FC07F09-9A3B-4E9B-9A06-D9AC6DD82535", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F923BEB3-D0A6-4FB8-95CA-4AF1369FAB08", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F9EC8D21-C6D4-4934-A9AF-AC23CB4FBF23", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD9F716E-DA62-473B-8057-D5C1ED9A6068", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "F24D151E-23F1-4EBF-8949-088F6A95C2F0", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "5C6BBD42-FFD8-474D-8ABA-A614B5F74508", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "7624379D-2965-44EF-9CB2-150F96A73D1A", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "78DB2C5D-9640-45E1-9D5C-12514E9C6C1B", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "00A20CE8-64D8-4F4B-9BF8-84A5D691051E", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "939BC44C-8CF2-4BA7-AC06-71B679BDF69A", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "A55E54A6-D4E3-48F8-AA94-6D28E709D86F", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "54718FCB-A8EE-4852-B406-0D3A41633A4F", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "DEC171BB-5A63-4D93-BAB4-E4C0743686C9", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "5AD85595-32CE-4517-A17F-E3E48114EE6B", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "3BEA0045-0186-406D-9827-2529ECEF4620", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "9FC6A58E-5F08-4D92-8640-D21C24A34B85", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "84402AA2-842C-4F45-BEEE-01B4399F8A2D", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E2E4D88D-B3B5-42A9-B3B6-E95BDCC1E805", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C994D446-1503-4AB9-BD8A-B3A6CFB0E423", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "E6635B2E-79F9-4E17-91DE-3147AEAAECD3", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "CF0503B6-5889-44EA-82BD-8975C69DC4EF", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "36B8EE53-5CD1-4CC9-9829-ED06BEB742C8", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "6215C280-42DB-4BC1-B6AB-C6A963B17830", "versionEndExcluding": "2022.1.6", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E920B994-CFAF-4585-BBFB-5BB453BB091A", "versionEndExcluding": "2023.1.7", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "88A19D6B-8863-4A0C-9422-53EF25653A22", "versionEndExcluding": "2024.1.7", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E858EBC9-08A6-480C-A896-C15A1D89FAF7", "versionEndExcluding": "2025.1.2", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo CATPART manipulado con fines maliciosos, al analizarse mediante Autodesk AutoCAD, puede forzar una vulnerabilidad de lectura fuera de los l\u00edmites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2025-1428", "lastModified": "2025-08-19T13:15:40.493", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2025-03-13T17:15:34.900", "references": [ { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/products/autodesk-access/overview" }, { "source": "psirt@autodesk.com", "url": "https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html" }, { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0001" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:45
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo PRT creado con fines malintencionados, cuando se analiza en odxug_dll.dll a trav\u00e9s de aplicaciones de Autodesk, puede forzar una escritura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-23150", "lastModified": "2025-05-06T19:45:43.800", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:11.803", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0010" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-787" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2024-06-25 04:15
Modified
2025-05-06 19:40
Severity ?
7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8 (High) - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
References
Impacted products
Vendor | Product | Version | |
---|---|---|---|
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_architecture | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_electrical | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_map_3d | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mechanical | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_mep | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | autocad_plant_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | civil_3d | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * | |
autodesk | advance_steel | * |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F055DD1C-AE4F-4F46-996E-204A51B09FC7", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "F0AECA1F-5E40-4EC9-9FB6-BE286D629C55", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "CAEB267C-721B-4AC9-96CE-C3DA951519ED", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*", "matchCriteriaId": "0B0EF835-F58E-4F6E-B35E-EDAB6F19A9CF", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "B244631D-FEED-490B-BE83-51B166DF7B78", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "1CA4601D-6F27-42E1-8685-0430583DEAA8", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "6EDB7216-3270-44FB-A236-19CCCD6052D1", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*", "matchCriteriaId": "55976EE6-BD1D-4DAB-9091-79962C64719C", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "24FD0AE9-5CBA-4D55-A76A-E8B642ABC4D9", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "8AE10283-8906-4A81-ACA0-14F7200AA204", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "DF1EF951-7456-4621-A64B-C5C37B21D0FA", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*", "matchCriteriaId": "9F533CA0-77A8-46BF-91B3-32A00500E23D", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "897AE769-8C96-4E4D-BE71-4851A183B725", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BBEFA684-46BD-4766-BF0B-48243175B61C", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F186FEF1-C88A-4F14-A30F-5B688FA5100C", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BFDF5574-487C-4F12-96AD-6CB85D170D84", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "0C25DA26-ACF6-4810-A515-BD0C387DBA42", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "93D53690-4790-401B-BEFF-528381C36218", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "92C4C49E-FBB7-431B-AE0F-2BC74DB08338", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*", "matchCriteriaId": "4937D51A-6B3B-4A7A-AD57-806814812946", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "0D4DDC78-6974-4097-BA37-F92B1194CDE2", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "E678BEF6-B064-401E-92C6-247EC258FE07", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "93BCB8FD-3AE4-4C9F-A2A6-0D63CC5EE0B4", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*", "matchCriteriaId": "70F538D1-54CE-47AF-ADDA-C530A154DD5E", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "CD7A1D9B-EF32-4415-BCC4-04E2A6972374", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "65D59F58-0AA2-4D15-8C75-146CAEC19584", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9B921-51F6-4A2B-A0AC-171FF1192C93", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF817DAD-6928-4155-B005-430342CDA30B", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "BF37A9E5-8B00-44AB-AFFF-CC89D2A96889", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "F1309864-F4E5-4BF7-8453-F863F8C463CF", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "7589C389-71FF-4E79-B51F-1C36FC72F81D", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*", "matchCriteriaId": "E35E9352-AEC7-4185-BCBC-103000D084BD", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "2E36BB72-4307-4DFC-AFC9-2A99EDEB5BB4", "versionEndExcluding": "2022.1.5", "versionStartIncluding": "2022", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "C56F6AFC-3A8A-4FEE-8D55-184129DD08F6", "versionEndExcluding": "2023.1.6", "versionStartIncluding": "2023", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "982A47A1-FAA7-45DB-A054-F13B13F3CA49", "versionEndExcluding": "2024.1.5", "versionStartIncluding": "2024", "vulnerable": true }, { "criteria": "cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*", "matchCriteriaId": "33337803-1300-419A-B980-7689C7C93F81", "versionEndExcluding": "2025.1", "versionStartIncluding": "2025", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process." }, { "lang": "es", "value": "Un archivo X_B y X_T creado con fines malintencionados, cuando se analiza en pskernel.DLL a trav\u00e9s de aplicaciones de Autodesk, puede forzar una lectura fuera de los l\u00edmites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar c\u00f3digo arbitrario en el contexto del proceso actual." } ], "id": "CVE-2024-37005", "lastModified": "2025-05-06T19:40:21.190", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "psirt@autodesk.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary" } ] }, "published": "2024-06-25T04:15:15.890", "references": [ { "source": "psirt@autodesk.com", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009" } ], "sourceIdentifier": "psirt@autodesk.com", "vulnStatus": "Analyzed", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "psirt@autodesk.com", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-125" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }