CVE-2023-41139

Severity
7.8HIGH
EPSS
0.1%
top 82.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23

Description

A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

NVDautodesk/autocad2023.0.02023.1.4+2
NVDautodesk/autocad_lt2024.0.02024.1.1+2
NVDautodesk/autocad_mep2024.0.02024.1.1+1
NVDautodesk/autocad_map_3d2024.0.02024.1.1+1
NVDautodesk/autocad_civil_3d2024.0.02024.1.1+1

🔴Vulnerability Details

2
GHSA
GHSA-7r6c-c52h-pf9p: A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer2023-11-23
CVEList
CVE-2023-41139: A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer2023-11-23
CVE-2023-41139 (HIGH CVSS 7.8) | A maliciously crafted STP file when | cvebase.io