Lucene search

K
cvelistAutodeskCVELIST:CVE-2024-23136
HistoryFeb 22, 2024 - 4:48 a.m.

CVE-2024-23136

2024-02-2204:48:25
CWE-822
autodesk
www.cve.org
autodesk autocad
stp file
code execution
asmkern228a.dll
pointer dereference
vulnerability

7.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.4%

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk AutoCAD can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "product": "AutoCAD, Advance Steel and Civil 3D",
    "vendor": "Autodesk",
    "versions": [
      {
        "status": "affected",
        "version": "2024, 2023, 2022, 2021"
      }
    ]
  }
]

7.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.4%

Related for CVELIST:CVE-2024-23136