Memory Corruption Vulnerability in Autodesk AutoCAD
CVE-2024-8597

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
29 October 2024

Summary

A vulnerability exists within Autodesk AutoCAD where a specially crafted STP file, when processed by the ASMDATAX230A.dll, can lead to a memory corruption scenario. This vulnerability enables a malicious actor to cause application crashes, manipulate sensitive data, or perform arbitrary code execution within the current process context. This poses a significant risk, as it can compromise system functionality and security if exploited.

Affected Version(s)

Advance Steel 2025 < 2025.1.1

Advance Steel 2024 < 2024.1.7

Advance Steel 2023 < 2023.1.7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.