CVE-2024-9489
published 2024-10-29CVE-2024-9489: A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.21%
10.9th percentile
A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| autodesk | advance_steel | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | advance_steel | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | advance_steel | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | advance_steel | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad_advance_steel | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad_architecture | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_architecture | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_architecture | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_architecture | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad_civil_3d | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad_electrical | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_electrical | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_electrical | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_electrical | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad_lt | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_lt | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_lt | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_lt | >= 2025 < 2025.1.1 | 2025.1.1 |
| autodesk | autocad_map_3d | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_map_3d | >= 2023 < 2023.1.7 | 2023.1.7 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_apache6.9
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v93x-fw33-f4pw: A maliciously crafted DWG file when parsed in ACAD
ghsa_unreviewed·2024-10-30
CVE-2024-9489 [HIGH] CWE-119 GHSA-v93x-fw33-f4pw: A maliciously crafted DWG file when parsed in ACAD
A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
Apache
Apache nifi: CVE-2024-52067
vendor_apache·CVSS 6.9
CVE-2024-52067 Apache nifi: CVE-2024-52067
Apache nifi: CVE-2024-52067
Title: Potential Insertion of Sensitive Parameter Values in Debug Log Published: 2024-11-20 Severity: Medium Products: Apache NiFi Affected Versions: 1.16.0 to 1.28.0 and 2.0.0-M1 to 2.0.0-M4 Fixed Versions: 1.28.1 and 2.0.0 Reporter: David Handermann References CVE Record: CVE-2024-52067 NVD Record: CVE-2024-52067 Apache Jira Issue: NIFI-13971 GitHub Pull Request: 9489 Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for framework flow synchronization, causing the application to write Parameter names and values to the application log. Parameter Context value
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-29
Published