CVE-2024-23140: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atfapi.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23140?
CVE-2024-23140 is considered a high-severity vulnerability due to the potential for arbitrary code execution and unauthorized access to sensitive information.
How do I fix CVE-2024-23140?
To fix CVE-2024-23140, users should update their Autodesk applications to the latest version provided by Autodesk that addresses this vulnerability.
What types of files are associated with CVE-2024-23140?
CVE-2024-23140 specifically pertains to maliciously crafted 3DM and MODEL file formats.
Which software is affected by CVE-2024-23140?
CVE-2024-23140 affects Autodesk applications, particularly Autodesk AutoCAD, when parsing specific file types.
What could happen if CVE-2024-23140 is exploited?
If exploited, CVE-2024-23140 can lead to application crashes, exposure of sensitive data, or execution of arbitrary code.