First published: Tue Jun 25 2024(Updated: )
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk AutoCAD 2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37006 has a high severity rating due to its potential to enable memory corruption and code execution in Autodesk applications.
To fix CVE-2024-37006, ensure that you update your Autodesk software to the latest version that includes security patches addressing this vulnerability.
CVE-2024-37006 affects Autodesk AutoCAD 2024 and possibly other Autodesk applications that utilize CC5Dll.dll.
CVE-2024-37006 can be exploited through a maliciously crafted CATPRODUCT file that leads to memory corruption and potential arbitrary code execution.
Currently, the best approach for CVE-2024-37006 is to avoid opening untrusted CATPRODUCT files until a patch is applied.