First published: Sun Mar 17 2024(Updated: )
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk DWG TrueView |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23138 is a high-severity vulnerability due to potential stack-based overflow leading to arbitrary code execution.
To mitigate CVE-2024-23138, update Autodesk DWG TrueView to the latest patched version provided by Autodesk.
An attacker can exploit CVE-2024-23138 to crash the application, read sensitive data, or execute arbitrary code.
CVE-2024-23138 specifically affects Autodesk DWG TrueView.
Testing for CVE-2024-23138 typically involves examining the handling of DWG files in Autodesk DWG TrueView for potential crashes or unauthorized access.