ZDI-24-296: Autodesk DWG TrueView DWG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk DWG TrueView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-23138.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-296?
The severity of ZDI-24-296 is critical due to its potential to allow remote code execution.
How do I fix ZDI-24-296?
To fix ZDI-24-296, users should update to the latest version of Autodesk DWG TrueView as recommended by the vendor.
What causes the ZDI-24-296 vulnerability?
ZDI-24-296 is caused by improper handling of user input in Autodesk DWG TrueView allowing arbitrary code execution.
Is user interaction required for exploiting ZDI-24-296?
Yes, user interaction is required for exploiting ZDI-24-296, as the user must visit a malicious page or open a malicious file.
What products are affected by ZDI-24-296?
ZDI-24-296 affects Autodesk DWG TrueView, particularly versions around 2022.