CVE-2024-23136

high

Description

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk AutoCAD can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

References

https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004

https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002

Details

Source: Mitre, NVD

Published: 2024-02-22

Updated: 2024-08-01

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High