CVE-2024-36999: Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products
A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36999?
CVE-2024-36999 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-36999?
To fix CVE-2024-36999, apply the latest security updates provided by Autodesk for affected software.
What software is affected by CVE-2024-36999?
CVE-2024-36999 affects Autodesk AutoCAD and AutoCAD-based products.
Can CVE-2024-36999 lead to data breaches?
Yes, CVE-2024-36999 can potentially lead to data breaches through sensitive data exposure.
What actions can a malicious actor take with CVE-2024-36999?
A malicious actor can exploit CVE-2024-36999 to crash the application, write sensitive data, or execute arbitrary code.