7.8
CVE-2024-23137
- EPSS 0.97%
- Veröffentlicht 22.02.2024 05:15:09
- Zuletzt bearbeitet 11.04.2025 15:55:06
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Autocad Architecture Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Architecture Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Architecture Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Architecture Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Architecture Version >= 2025 < 2025.0.1
Autodesk ≫ Autocad Electrical Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Electrical Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Electrical Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Electrical Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Electrical Version >= 2025 < 2025.0.1
Autodesk ≫ Autocad Mechanical Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Mechanical Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Mechanical Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Mechanical Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Mechanical Version >= 2025 < 2025.0.1
Autodesk ≫ Autocad Mep Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Mep Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Mep Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Mep Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Mep Version >= 2025 < 2025.0.1
Autodesk ≫ Autocad Plant 3d Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Plant 3d Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Plant 3d Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Plant 3d Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Plant 3d Version >= 2025 < 2025.0.1
Autodesk ≫ Advance Steel Version >= 2021 < 2021.1.4
Autodesk ≫ Advance Steel Version >= 2022 < 2022.1.4
Autodesk ≫ Advance Steel Version >= 2023 < 2023.1.5
Autodesk ≫ Advance Steel Version >= 2024 < 2024.1.3
Autodesk ≫ Advance Steel Version >= 2025 < 2025.0.1
Autodesk ≫ Autocad Map 3d Version >= 2021 < 2021.1.4
Autodesk ≫ Autocad Map 3d Version >= 2022 < 2022.1.4
Autodesk ≫ Autocad Map 3d Version >= 2023 < 2023.1.5
Autodesk ≫ Autocad Map 3d Version >= 2024 < 2024.1.3
Autodesk ≫ Autocad Map 3d Version >= 2025 < 2025.0.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.97% | 0.572 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| psirt@autodesk.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-457 Use of Uninitialized Variable
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0009