A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Autodesk
Autodesk autocad Autodesk autocad Advance Steel Autodesk autocad Civil 3d |
|
CPEs | cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2025:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2025:*:*:*:*:*:*:* |
|
Vendors & Products |
Autodesk
Autodesk autocad Autodesk autocad Advance Steel Autodesk autocad Civil 3d |
|
Metrics |
ssvc
|
Tue, 28 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software | |
Metrics |
cvssV3_1
|
cvssV3_1
|

Status: PUBLISHED
Assigner: autodesk
Published:
Updated: 2025-01-28T16:44:58.568Z
Reserved: 2024-01-11T21:47:40.856Z
Link: CVE-2024-23131

Updated: 2024-08-01T22:59:31.784Z

Status : Awaiting Analysis
Published: 2024-02-22T04:15:08.797
Modified: 2025-01-28T17:15:19.420
Link: CVE-2024-23131

No data.