Memory Corruption Vulnerability in Autodesk AutoCAD
CVE-2024-8597
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 29 October 2024
Summary
A vulnerability exists within Autodesk AutoCAD where a specially crafted STP file, when processed by the ASMDATAX230A.dll, can lead to a memory corruption scenario. This vulnerability enables a malicious actor to cause application crashes, manipulate sensitive data, or perform arbitrary code execution within the current process context. This poses a significant risk, as it can compromise system functionality and security if exploited.
Affected Version(s)
Advance Steel 2025 < 2025.1.1
Advance Steel 2024 < 2024.1.7
Advance Steel 2023 < 2023.1.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published