CVE-2024-8592
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A maliciously crafted CATPART file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 | |
| From 2024 to 2024.1.6 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Related CWEs
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (1)
Source: psirt@autodesk.com
Vendor Advisory
Timeline
No history available yet.