A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Feb 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process. | A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
Tue, 28 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Autodesk
Autodesk autocad Autodesk autocad Advance Steel Autodesk autocad Architecture Autodesk autocad Civil 3d Autodesk autocad Electrical Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d |
|
CPEs | cpe:2.3:a:autodesk:autocad:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:2024.1.5:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:2024.1.5:*:*:*:*:*:*:* |
|
Vendors & Products |
Autodesk
Autodesk autocad Autodesk autocad Advance Steel Autodesk autocad Architecture Autodesk autocad Civil 3d Autodesk autocad Electrical Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d |
|
Metrics |
ssvc
|
Tue, 28 Jan 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Multiple ZDI Vulnerabilities in Autodesk AutoCAD and certain AutoCAD-based products | |
Metrics |
cvssV3_1
|
cvssV3_1
|

Status: PUBLISHED
Assigner: autodesk
Published:
Updated: 2025-02-10T20:53:40.826Z
Reserved: 2024-05-30T20:11:46.548Z
Link: CVE-2024-36999

Updated: 2024-08-02T03:43:50.596Z

Status : Awaiting Analysis
Published: 2024-06-25T04:15:15.147
Modified: 2025-02-10T21:15:18.677
Link: CVE-2024-36999

No data.