CVE-2024-23154: Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products
A maliciously crafted SLDPRT file, when parsed in ODXSWDLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23154?
CVE-2024-23154 is classified as having a high severity due to its potential for remote code execution and data exposure.
How do I fix CVE-2024-23154?
To fix CVE-2024-23154, users should apply the latest security patches provided by Autodesk for affected applications.
What types of software are affected by CVE-2024-23154?
CVE-2024-23154 affects Autodesk AutoCAD and AutoCAD-based products that utilize the ODXSW_DLL.dll.
What are the potential impacts of CVE-2024-23154?
The potential impacts of CVE-2024-23154 include application crashes, unauthorized access to sensitive data, and arbitrary code execution.
Who is vulnerable to CVE-2024-23154?
Any user operating Autodesk AutoCAD or related products is vulnerable to CVE-2024-23154 if not updated to a secure version.