Autodesk AutoCAD Vulnerability: Use-After-Free Flaw Allows Attackers to Crash, Write Data or Execute Code
CVE-2024-8590
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 29 October 2024
Summary
A Use-After-Free vulnerability exists in the atf_api.dll component of Autodesk AutoCAD. This vulnerability arises when a maliciously crafted 3DM file is parsed, leading to potential crashes, the unwarranted writing of sensitive data, or unauthorized execution of arbitrary code within the context of the current process. Malicious actors can exploit this vulnerability to compromise system integrity and potentially gain unauthorized access to sensitive information.
Affected Version(s)
Advance Steel 2025 < 2025.1.1
Advance Steel 2024 < 2024.1.7
Advance Steel 2023 < 2023.1.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published