CVE-2024-23152: Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23152?
CVE-2024-23152 is categorized as a high severity vulnerability due to the potential for out-of-bounds read, which can lead to crashes and arbitrary code execution.
How do I fix CVE-2024-23152?
To mitigate CVE-2024-23152, users should update their Autodesk software to the latest version that addresses this vulnerability.
Which Autodesk products are affected by CVE-2024-23152?
CVE-2024-23152 affects Autodesk AutoCAD and AutoCAD-based products.
What can a malicious actor do using CVE-2024-23152?
A malicious actor can exploit CVE-2024-23152 to crash the application, read sensitive data, or execute arbitrary code.
Is there a workaround for CVE-2024-23152 until a patch is available?
As of now, no specific workarounds have been provided for CVE-2024-23152, so it is recommended to apply the latest updates from Autodesk.