CVE-2024-23159: Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products
A maliciously crafted STP file, when parsed in stpaimx64vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23159?
CVE-2024-23159 has been rated as a critical vulnerability due to its potential for code execution.
How do I fix CVE-2024-23159?
To fix CVE-2024-23159, ensure that you update your Autodesk applications to the latest patches provided by Autodesk.
What products are affected by CVE-2024-23159?
CVE-2024-23159 affects Autodesk AutoCAD and other AutoCAD-based products.
What is the impact of CVE-2024-23159?
The impact of CVE-2024-23159 includes the risk of code execution due to uninitialized variables in the processing of STP files.
Is there a workaround for CVE-2024-23159?
Currently, there are no known workarounds for CVE-2024-23159 other than applying the available updates.