ZeroHour

CVE-2024-23142

CVSS 3.1
7.8 high
EPSS
<1%p37
Published
()
Modified
Description

A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Vendors
autodesk
Products
autocad, autocad architecture, autocad electrical, autocad map 3d, autocad mechanical, autocad mep, autocad plant 3d, civil 3d, advance steel
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.