First published: Tue Jun 25 2024(Updated: )
A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD 2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23149 has a high severity rating due to its potential to cause crashes and expose sensitive data.
To fix CVE-2024-23149, ensure that you are using the latest version of Autodesk AutoCAD, which includes security patches.
CVE-2024-23149 can be exploited to cause crashes, read sensitive data, or execute arbitrary code.
CVE-2024-23149 specifically affects Autodesk AutoCAD 2024.
CVE-2024-23149 may be exploited through specially crafted SLDDRW files, making remote exploitation feasible.