A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
Link | Resource |
---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory |
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory |
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
History
11 Apr 2025, 15:55
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
CPE | cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* |
|
First Time |
Autodesk civil 3d
Autodesk autocad Electrical Autodesk autocad Mep Autodesk autocad Map 3d Autodesk autocad Plant 3d Autodesk autocad Architecture Autodesk autocad Mechanical Autodesk advance Steel Autodesk Autodesk autocad |
|
References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 - Vendor Advisory | |
References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 - Vendor Advisory |
27 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
Information
Published : 2024-02-22 05:15
Updated : 2025-04-11 15:55
NVD link : CVE-2024-23136
Mitre link : CVE-2024-23136
CVE.ORG link : CVE-2024-23136
JSON object : View
Products Affected
autodesk
- autocad_architecture
- advance_steel
- autocad
- autocad_plant_3d
- civil_3d
- autocad_map_3d
- autocad_mep
- autocad_mechanical
- autocad_electrical
CWE