First published: Thu Feb 22 2024(Updated: )
A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD 2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23137 is currently classified as critical due to its potential to allow code execution.
To fix CVE-2024-23137, users should apply the latest security updates or patches provided by Autodesk for affected applications.
CVE-2024-23137 specifically affects Autodesk AutoCAD when parsing malicious STP or SLDPRT files.
Yes, CVE-2024-23137 can potentially be exploited remotely through specially crafted files.
CVE-2024-23137 is associated with STP and SLDPRT file types that can be parsed by Autodesk applications.