Autodesk DWG TrueView Vulnerability Could Lead to Stack-based Overflow
CVE-2024-23138

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
18 March 2024

Badges

📰 News Worthy

Summary

A vulnerability exists in Autodesk DWG TrueView, which can be exploited through a specially crafted DWG file. When this file is parsed, it can trigger a stack-based overflow, potentially allowing an attacker to crash the application, read sensitive information, or execute arbitrary code in the context of the affected process. This vulnerability underscores the importance of careful file handling and security practices when using Autodesk software.

Affected Version(s)

Advance Steel 2024 < 2024.1.3

Advance Steel 2023 < 2023.1.5

Advance Steel 2022 < 2022.1.4

News Articles

CVE-2024-23138 Archives

VulnerabilityMarch 17, 2024CVE-2024-23138 &amp; 23139: Autodesk Patches Critical Flaws in Popular Design SoftwareAutodesk, a leader in the design and engineering software industry, has released critical...

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by securityonline.info

  • Vulnerability published

.
CVE-2024-23138 : Autodesk DWG TrueView Vulnerability Could Lead to Stack-based Overflow | SecurityVulnerability.io