First published: Thu Feb 22 2024(Updated: )
A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD 2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23127 is classified as a critical severity vulnerability due to its potential to cause heap-based overflows.
To mitigate CVE-2024-23127, ensure all Autodesk software is updated to the latest version that addresses this vulnerability.
CVE-2024-23127 can be exploited using maliciously crafted MODEL, SLDPRT, or SLDASM files.
CVE-2024-23127 affects Autodesk AutoCAD 2024 through specific dynamic link libraries.
CVE-2024-23127 can lead to application crashes, unauthorized reading of sensitive data, or execution of arbitrary code.