CVE-2024-23141: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
Published Jun 25, 2024
·Updated
A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
Affected Software
37 affected components
Autodesk AutoCAD
Autodesk AutoCAD>=2022<2022.1.5
Autodesk AutoCAD>=2023<2023.1.6
Autodesk AutoCAD>=2024<2024.1.4
Autodesk AutoCAD>=2025<2025.1
Autodesk AutoCAD Architecture>=2022<2022.1.5
Autodesk AutoCAD Architecture>=2023<2023.1.6
Autodesk AutoCAD Architecture>=2024<2024.1.4
Autodesk AutoCAD Architecture>=2025<2025.1
Autodesk AutoCAD Electrical>=2022<2022.1.5
Autodesk AutoCAD Electrical>=2023<2023.1.6
Autodesk AutoCAD Electrical>=2024<2024.1.4
Autodesk AutoCAD Electrical>=2025<2025.1
Autodesk AutoCAD Map 3D>=2022<2022.1.5
Autodesk AutoCAD Map 3D>=2023<2023.1.6
Autodesk AutoCAD Map 3D>=2024<2024.1.4
Autodesk AutoCAD Map 3D>=2025<2025.1
Autodesk AutoCAD Mechanical>=2022<2022.1.5
Autodesk AutoCAD Mechanical>=2023<2023.1.6
Autodesk AutoCAD Mechanical>=2024<2024.1.4
Autodesk AutoCAD Mechanical>=2025<2025.1
Autodesk AutoCAD MEP>=2022<2022.1.5
Autodesk AutoCAD MEP>=2023<2023.1.6
Autodesk AutoCAD MEP>=2024<2024.1.4
Autodesk AutoCAD MEP>=2025<2025.1
Autodesk AutoCAD Plant 3D>=2022<2022.1.5
Autodesk AutoCAD Plant 3D>=2023<2023.1.6
Autodesk AutoCAD Plant 3D>=2024<2024.1.4
Autodesk AutoCAD Plant 3D>=2025<2025.1
Autodesk Civil 3D>=2022<2022.1.5
Autodesk Civil 3D>=2023<2023.1.6
Autodesk Civil 3D>=2024<2024.1.4
Autodesk Civil 3D>=2025<2025.1
Autodesk Advance Steel>=2022<2022.1.5
Autodesk Advance Steel>=2023<2023.1.6
Autodesk Advance Steel>=2024<2024.1.4
Autodesk Advance Steel>=2025<2025.1
Event History
Jun 25, 2024
CVE Published
via MITRE·01:22 AM
Data Sourced
via MITRE·01:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23141?
CVE-2024-23141 is considered to have a critical severity due to its potential for code execution.
2
How do I fix CVE-2024-23141?
To fix CVE-2024-23141, update to the latest version of Autodesk AutoCAD as recommended by Autodesk.
3
What types of applications are affected by CVE-2024-23141?
CVE-2024-23141 affects Autodesk applications that utilize the libodxdll for parsing MODEL files.
4
Can CVE-2024-23141 be exploited remotely?
Yes, CVE-2024-23141 can potentially be exploited remotely if a user opens a malicious MODEL file.
5
What kind of impact can CVE-2024-23141 have on my system?
The impact of CVE-2024-23141 can include arbitrary code execution in the context of the current process, potentially compromising the system.