Autodesk AutoCAD Vulnerable to Malicious MODEL File Parsing
CVE-2024-8596
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 29 October 2024
Summary
An out-of-bound write vulnerability exists in Autodesk AutoCAD resulting from improper parsing of maliciously crafted MODEL files through the libodxdll.dll component. Attackers exploiting this flaw can potentially crash the software, write sensitive information, or execute arbitrary code within the context of the running process. This poses significant risks to users and organizations relying on Autodesk's design tools, prompting the need for immediate attention and rectification as outlined in the Autodesk security advisory.
Affected Version(s)
Advance Steel 2025 < 2025.1.1
Advance Steel 2024 < 2024.1.7
Advance Steel 2023 < 2023.1.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published