CVE-2024-0446: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0446?
CVE-2024-0446 has a high severity rating due to its potential to cause crashes, sensitive data leaks, or arbitrary code execution.
How can I fix CVE-2024-0446?
To mitigate CVE-2024-0446, ensure you are using the latest version of Autodesk products and apply all available security updates.
What types of files are associated with CVE-2024-0446?
CVE-2024-0446 is associated with maliciously crafted STP, CATPART, or MODEL files.
Which Autodesk applications are affected by CVE-2024-0446?
CVE-2024-0446 affects various Autodesk applications that make use of ASMKERN228A.dll and ASMdatax229A.dll.
What can an attacker achieve by exploiting CVE-2024-0446?
An attacker exploiting CVE-2024-0446 can potentially crash the application, access sensitive information, or execute arbitrary code.