Autodesk AutoCAD Vulnerability Could Lead to Crashes, Data Writing, or Code Execution
CVE-2024-8589
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 29 October 2024
Summary
A vulnerability exists in Autodesk AutoCAD due to improper handling of maliciously crafted SLDPRT files. When the odxsw_dll.dll component processes these files, it may lead to an Out-of-Bounds Read condition, allowing an attacker to potentially manipulate application behavior. This could result in application crashes, unauthorized access to sensitive data, or the execution of arbitrary code within the context of the running process, thereby compromising system security.
Affected Version(s)
Advance Steel 2025 < 2025.1.1
Advance Steel 2024 < 2024.1.7
Advance Steel 2023 < 2023.1.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published