CVE-2024-23120: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23120?
CVE-2024-23120 is classified as a critical vulnerability due to its potential for data corruption and arbitrary code execution.
How do I fix CVE-2024-23120?
To mitigate CVE-2024-23120, ensure that you apply the latest security patches and updates provided by Autodesk for AutoCAD.
What types of files exploit CVE-2024-23120?
CVE-2024-23120 is exploited through specially crafted STP and STEP files that, when processed by Autodesk AutoCAD, trigger the vulnerability.
Which versions of AutoCAD are affected by CVE-2024-23120?
CVE-2024-23120 affects various versions of Autodesk AutoCAD that utilize the ASMIMPORT228A.dll and ASMIMPORT229A.dll components.
What are the potential impacts of CVE-2024-23120?
Exploiting CVE-2024-23120 can lead to application crashes, data corruption, or execution of arbitrary code on affected systems.