CVE-2024-23131: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23131?
CVE-2024-23131 has been rated as a critical memory corruption vulnerability that can lead to application crashes and unauthorized access.
How do I fix CVE-2024-23131?
To fix CVE-2024-23131, users should apply the latest security updates provided by Autodesk for affected applications.
What applications are affected by CVE-2024-23131?
CVE-2024-23131 affects Autodesk AutoCAD 2024 when parsing malicious STP files in specific DLLs.
What types of attacks can CVE-2024-23131 facilitate?
CVE-2024-23131 can allow attackers to execute arbitrary code through memory corruption via crafted STP files.
Is there a workaround for CVE-2024-23131?
Currently, Autodesk has not provided a specific workaround for CVE-2024-23131, and users are encouraged to update their software.