CVE-2024-23127: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSWDLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23127?
CVE-2024-23127 is classified as a critical severity vulnerability due to its potential to cause heap-based overflows.
How do I fix CVE-2024-23127?
To mitigate CVE-2024-23127, ensure all Autodesk software is updated to the latest version that addresses this vulnerability.
What types of files can exploit CVE-2024-23127?
CVE-2024-23127 can be exploited using maliciously crafted MODEL, SLDPRT, or SLDASM files.
Which Autodesk applications are affected by CVE-2024-23127?
CVE-2024-23127 affects Autodesk AutoCAD 2024 through specific dynamic link libraries.
What potential impacts does CVE-2024-23127 have?
CVE-2024-23127 can lead to application crashes, unauthorized reading of sensitive data, or execution of arbitrary code.