cbcvebase.
CVE-2024-23143
published 2024-06-25

CVE-2024-23143: A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
autodeskadvance_steel>= 2022 < 2022.1.52022.1.5
autodeskadvance_steel>= 2023 < 2023.1.62023.1.6
autodeskadvance_steel>= 2024 < 2024.1.42024.1.4
autodeskadvance_steel>= 2025 < 2025.12025.1
autodeskautocad>= 2022 < 2022.1.52022.1.5
autodeskautocad>= 2023 < 2023.1.62023.1.6
autodeskautocad>= 2024 < 2024.1.42024.1.4
autodeskautocad>= 2025 < 2025.12025.1
autodeskautocad_architecture>= 2022 < 2022.1.52022.1.5
autodeskautocad_architecture>= 2023 < 2023.1.62023.1.6
autodeskautocad_architecture>= 2024 < 2024.1.42024.1.4
autodeskautocad_architecture>= 2025 < 2025.12025.1
autodeskautocad_electrical>= 2022 < 2022.1.52022.1.5
autodeskautocad_electrical>= 2023 < 2023.1.62023.1.6
autodeskautocad_electrical>= 2024 < 2024.1.42024.1.4
autodeskautocad_electrical>= 2025 < 2025.12025.1
autodeskautocad_map_3d>= 2022 < 2022.1.52022.1.5
autodeskautocad_map_3d>= 2023 < 2023.1.62023.1.6
autodeskautocad_map_3d>= 2024 < 2024.1.42024.1.4
autodeskautocad_map_3d>= 2025 < 2025.12025.1
autodeskautocad_mechanical>= 2022 < 2022.1.52022.1.5
autodeskautocad_mechanical>= 2023 < 2023.1.62023.1.6
autodeskautocad_mechanical>= 2024 < 2024.1.42024.1.4
autodeskautocad_mechanical>= 2025 < 2025.12025.1
autodeskautocad_mep>= 2022 < 2022.1.52022.1.5