First published: Tue Jun 25 2024(Updated: )
A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37003 is considered a high-severity vulnerability due to its potential to cause stack-based overflow and execute arbitrary code.
To remediate CVE-2024-37003, ensure all Autodesk applications are updated to the latest version that addresses this vulnerability.
CVE-2024-37003 can be exploited through maliciously crafted DWG and SLDPRT files processed by Autodesk applications.
Yes, CVE-2024-37003 can potentially allow an attacker to read sensitive data from the affected system.
CVE-2024-37003 specifically affects Autodesk AutoCAD Desktop Software.