cbcvebase.
CVE-2024-23159
published 2024-06-25

CVE-2024-23159: A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
autodeskadvance_steel>= 2022 < 2022.1.52022.1.5
autodeskadvance_steel>= 2023 < 2023.1.62023.1.6
autodeskadvance_steel>= 2024 < 2024.1.52024.1.5
autodeskadvance_steel>= 2025 < 2025.12025.1
autodeskautocad>= 2022 < 2022.1.52022.1.5
autodeskautocad>= 2023 < 2023.1.62023.1.6
autodeskautocad>= 2024 < 2024.1.52024.1.5
autodeskautocad>= 2025 < 2025.12025.1
autodeskautocad_architecture>= 2022 < 2022.1.52022.1.5
autodeskautocad_architecture>= 2023 < 2023.1.62023.1.6
autodeskautocad_architecture>= 2024 < 2024.1.52024.1.5
autodeskautocad_architecture>= 2025 < 2025.12025.1
autodeskautocad_electrical>= 2022 < 2022.1.52022.1.5
autodeskautocad_electrical>= 2023 < 2023.1.62023.1.6
autodeskautocad_electrical>= 2024 < 2024.1.52024.1.5
autodeskautocad_electrical>= 2025 < 2025.12025.1
autodeskautocad_map_3d>= 2022 < 2022.1.52022.1.5
autodeskautocad_map_3d>= 2023 < 2023.1.62023.1.6
autodeskautocad_map_3d>= 2024 < 2024.1.52024.1.5
autodeskautocad_map_3d>= 2025 < 2025.12025.1
autodeskautocad_mechanical>= 2022 < 2022.1.52022.1.5
autodeskautocad_mechanical>= 2023 < 2023.1.62023.1.6
autodeskautocad_mechanical>= 2024 < 2024.1.52024.1.5
autodeskautocad_mechanical>= 2025 < 2025.12025.1
autodeskautocad_mep>= 2022 < 2022.1.52022.1.5