CVE-2023-29076

CWE-119Buffer Overflow3 documents3 sources
Severity
9.8CRITICAL
EPSS
0.3%
top 46.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23

Description

A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages10 packages

NVDautodesk/autocad2023.0.02023.1.4+2
NVDautodesk/autocad_lt2024.0.02024.1.1+2
NVDautodesk/autocad_mep2024.0.02024.1.1+1
NVDautodesk/autocad_map_3d2024.0.02024.1.1+1
NVDautodesk/autocad_civil_3d2024.0.02024.1.1+1

🔴Vulnerability Details

2
CVEList
CVE-2023-29076: A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabilit2023-11-23
GHSA
GHSA-rrpv-wj77-67hf: A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabilit2023-11-23
CVE-2023-29076 (CRITICAL CVSS 9.8) | A maliciously crafted MODEL | cvebase.io