First published: Tue Jun 25 2024(Updated: )
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD | ||
Autodesk Civil 3D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23148 is critical due to its potential for memory corruption and possible code execution.
To fix CVE-2024-23148, ensure that you update your Autodesk applications to the latest version provided by Autodesk.
CVE-2024-23148 affects Autodesk applications, specifically AutoCAD and CC5Dll.dll.
Yes, CVE-2024-23148 can lead to unauthorized code execution, potentially resulting in data breaches if exploited.
CVE-2024-23148 can be exploited through specially crafted CATPRODUCT files that trigger memory corruption vulnerabilities.