CVE-2024-23149: Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
A maliciously crafted SLDDRW file, when parsed in ODXSWDLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23149?
CVE-2024-23149 has a high severity rating due to its potential to cause crashes and expose sensitive data.
How do I fix CVE-2024-23149?
To fix CVE-2024-23149, ensure that you are using the latest version of Autodesk AutoCAD, which includes security patches.
What type of attacks can CVE-2024-23149 lead to?
CVE-2024-23149 can be exploited to cause crashes, read sensitive data, or execute arbitrary code.
What products are affected by CVE-2024-23149?
CVE-2024-23149 specifically affects Autodesk AutoCAD 2024.
Can CVE-2024-23149 be exploited remotely?
CVE-2024-23149 may be exploited through specially crafted SLDDRW files, making remote exploitation feasible.