CVE-2024-23159

HIGH

Autodesk Autocad < 2022.1.5 - Use of Uninitialized Resource

Title source: rule
STIX 2.1

Description

A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Scores

CVSS v3 7.8
EPSS 0.0080
EPSS Percentile 74.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-457 CWE-908
Status published
Products (9)
autodesk/advance_steel 2022 - 2022.1.5
autodesk/autocad 2022 - 2022.1.5
autodesk/autocad_architecture 2022 - 2022.1.5
autodesk/autocad_electrical 2022 - 2022.1.5
autodesk/autocad_map_3d 2022 - 2022.1.5
autodesk/autocad_mechanical 2022 - 2022.1.5
autodesk/autocad_mep 2022 - 2022.1.5
autodesk/autocad_plant_3d 2022 - 2022.1.5
autodesk/civil_3d 2022 - 2022.1.5
Published Jun 25, 2024
Tracked Since Feb 18, 2026