Autodesk AutoCAD Vulnerability Allows for Out-of-Bounds Write and Code Execution
CVE-2024-7991
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 29 October 2024
Summary
A vulnerability in Autodesk AutoCAD and specific AutoCAD-based products enables a maliciously crafted DWG file to trigger an out-of-bounds write. When these files are processed, a malicious actor can exploit this flaw to cause application crashes, read sensitive data from the memory, or execute arbitrary code within the affected application’s process. This type of attack can compromise system integrity and expose critical information, highlighting the importance of timely patching and adhering to security advisories.
Affected Version(s)
Advance Steel 2025 < 2025.1.1
Advance Steel 2024 < 2024.1.7
Advance Steel 2023 < 2023.1.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published