CVE-2024-23138: Stack-based Overflow Vulnerability in the TrueViewTM Desktop Software
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23138?
CVE-2024-23138 is a high-severity vulnerability due to potential stack-based overflow leading to arbitrary code execution.
How do I fix CVE-2024-23138?
To mitigate CVE-2024-23138, update Autodesk DWG TrueView to the latest patched version provided by Autodesk.
What can an attacker achieve by exploiting CVE-2024-23138?
An attacker can exploit CVE-2024-23138 to crash the application, read sensitive data, or execute arbitrary code.
What software is affected by CVE-2024-23138?
CVE-2024-23138 specifically affects Autodesk DWG TrueView.
Is there a direct way to test for CVE-2024-23138 in my environment?
Testing for CVE-2024-23138 typically involves examining the handling of DWG files in Autodesk DWG TrueView for potential crashes or unauthorized access.