CVE-2024-8590: Autodesk AutoCAD 3DM File Parsing Use-After-Free Code Execution Vulnerability
Published Oct 29, 2024
·Updated
A maliciously crafted 3DM file when parsed in atfapi.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
9 affected components
All of the following
Any of the following
Autodesk AutoCAD>=2025<2025.1.1
Autodesk Autocad Advance Steel>=2025<2025.1.1
Autodesk AutoCAD Architecture>=2025<2025.1.1
Autodesk Autocad Civil 3d>=2025<2025.1.1
Autodesk AutoCAD Electrical>=2025<2025.1.1
Autodesk AutoCAD Mechanical>=2025<2025.1.1
Autodesk AutoCAD MEP>=2025<2025.1.1
Autodesk AutoCAD Plant 3D>=2025<2025.1.1
Microsoft Windows
Event History
Oct 29, 2024
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8590?
CVE-2024-8590 is a critical vulnerability that can lead to arbitrary code execution.
2
How do I fix CVE-2024-8590?
To fix CVE-2024-8590, users should update Autodesk AutoCAD to the latest version beyond 2025.1.1.
3
What software is affected by CVE-2024-8590?
CVE-2024-8590 affects various Autodesk AutoCAD products released from version 2025 to 2025.1.1.
4
Can CVE-2024-8590 lead to data exposure?
Yes, CVE-2024-8590 can allow a malicious actor to write sensitive data and potentially expose it.
5
What type of vulnerability is CVE-2024-8590?
CVE-2024-8590 is classified as a Use-After-Free vulnerability.