CVE-2024-23136

HIGH

Autodesk - Code Injection

Title source: llm
STIX 2.1

Description

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 58.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-822
Status published
Products (9)
autodesk/advance_steel 2021 - 2021.1.4
autodesk/autocad 2021 - 2021.1.4
autodesk/autocad_architecture 2021 - 2021.1.4
autodesk/autocad_electrical 2021 - 2021.1.4
autodesk/autocad_map_3d 2021 - 2021.1.4
autodesk/autocad_mechanical 2021 - 2021.1.4
autodesk/autocad_mep 2021 - 2021.1.4
autodesk/autocad_plant_3d 2021 - 2021.1.4
autodesk/civil_3d 2021 - 2021.1.4
Published Feb 22, 2024
Tracked Since Feb 18, 2026