CVE-2024-23136Untrusted Pointer Dereference in Advance Steel

Severity
7.8HIGHNVD
EPSS
0.4%
top 41.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22

Description

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages18 packages

CVEListV5autodesk/autocad20252025.0.1+4
NVDautodesk/autocad20212021.1.4+4
CVEListV5autodesk/civil_3d20252025.0.1+4
NVDautodesk/civil_3d20212021.1.4+4
CVEListV5autodesk/autocad_mep20252025.0.1+4

🔴Vulnerability Details

2
CVEList
Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software2024-02-22
GHSA
GHSA-rxxm-q32v-2mc5: A maliciously crafted STP file when ASMKERN228A2024-02-22
CVE-2024-23136 — Untrusted Pointer Dereference | cvebase