CVE-2024-23131

HIGH

Autodesk AutoCAD Family < 2021.1.4 - Memory Corruption via Malicious STP File

Title source: llm
STIX 2.1

Description

A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

Scores

CVSS v3 7.8
EPSS 0.0032
EPSS Percentile 54.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (9)
autodesk/advance_steel 2021 - 2021.1.4
autodesk/autocad 2021 - 2021.1.4
autodesk/autocad_architecture 2021 - 2021.1.4
autodesk/autocad_electrical 2021 - 2021.1.4
autodesk/autocad_map_3d 2021 - 2021.1.4
autodesk/autocad_mechanical 2021 - 2021.1.4
autodesk/autocad_mep 2021 - 2021.1.4
autodesk/autocad_plant_3d 2021 - 2021.1.4
autodesk/civil_3d 2021 - 2021.1.4
Published Feb 22, 2024
Tracked Since Feb 18, 2026