← Back

CVE-2024-23136

nvd nist
Published: Feb 22, 2024Modified: Dec 31, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: psirt@autodesk.com (Secondary)

Description

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Affected (45)

9 products
Autocad Electrical
Autocad Mechanical
Autocad Mep
Autocad Plant 3d
Civil 3d
Advance Steel
Autocad Map 3d
Autocad
Autocad Architecture
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration D
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration F
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration G
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration H
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1
Configuration I
5 vulnerable
Vulnerable SoftwareAffected Versions
Autodesk
From 2021 to 2021.1.4
From 2022 to 2022.1.4
From 2023 to 2023.1.5
From 2024 to 2024.1.3
From 2025 to 2025.0.1

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.