CVE-2023-29073: Buffer Overflow
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-29073?
CVE-2023-29073 is a vulnerability in Autodesk AutoCAD 2024 and 2023 that allows a maliciously crafted MODEL file to cause a Heap-Based Buffer Overflow, leading to potential crashes, data leaks, or execution of arbitrary code.
How severe is CVE-2023-29073?
CVE-2023-29073 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
Which software versions are affected by CVE-2023-29073?
CVE-2023-29073 affects Autodesk AutoCAD 2024 versions up to and excluding 2024.1.1, and Autodesk AutoCAD 2023 versions from 2023.0.0 to 2023.1.4.
How can CVE-2023-29073 be exploited?
CVE-2023-29073 can be exploited by parsing a maliciously crafted MODEL file through Autodesk AutoCAD 2024 or 2023.
Is there a fix available for CVE-2023-29073?
Yes, Autodesk has released a security advisory with mitigation measures and updates to address the CVE-2023-29073 vulnerability. Please refer to their official website for more information.