CVE-2024-37002Use of Uninitialized Variable in Advance Steel

Severity
7.8HIGHNVD
EPSS
0.1%
top 64.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25

Description

A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages18 packages

CVEListV5autodesk/autocad20252025.1+3
NVDautodesk/autocad20222022.1.5+3
CVEListV5autodesk/civil_3d20252025.1+3
NVDautodesk/civil_3d20222022.1.5+3
CVEListV5autodesk/autocad_mep20252025.1+3

🔴Vulnerability Details

2
CVEList
Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software2024-06-25
GHSA
GHSA-354c-38ff-3cw6: A maliciously crafted MODEL file, when parsed in ASMkern229A2024-06-25
CVE-2024-37002 — Use of Uninitialized Variable | cvebase