CVE-2024-23142: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted CATPART, STP, and MODEL file, when parsed in atfdwgconsumer.dll, rosex64vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23142?
CVE-2024-23142 is considered a critical severity vulnerability due to its potential to allow code execution.
How does CVE-2024-23142 exploit Autodesk applications?
CVE-2024-23142 exploits Autodesk applications by using malicious CATPART, STP, and MODEL files that trigger a use-after-free condition.
What versions of Autodesk AutoCAD are affected by CVE-2024-23142?
CVE-2024-23142 affects all versions of Autodesk AutoCAD that utilize atf_dwg_consumer.dll, rose_x64_vc15.dll, and libodxdll.
What should I do if my system is vulnerable to CVE-2024-23142?
To mitigate CVE-2024-23142, ensure you update Autodesk AutoCAD to the latest version provided by the vendor.
Can CVE-2024-23142 allow for remote code execution?
Yes, CVE-2024-23142 can potentially lead to remote code execution if exploited by an attacker.