CVE-2024-23137

A maliciously crafted STP or SLDPRT file in ODXSW_DLL.dll when parsed through Autodesk AutoCAD can be used to uninitialized variable. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
CVSS

No CVSS.

Configurations

No configuration.

History

18 Mar 2024, 00:15

Type Values Removed Values Added
References
  • () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 -
Summary (en) A maliciously crafted STP or SLDPRT file when ODXSW_DLL.dll parsed through Autodesk AutoCAD can be used to uninitialized variable. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. (en) A maliciously crafted STP or SLDPRT file in ODXSW_DLL.dll when parsed through Autodesk AutoCAD can be used to uninitialized variable. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

22 Feb 2024, 19:07

Type Values Removed Values Added
Summary
  • (es) Un archivo STP o SLDPRT creado con fines malintencionados cuando ODXSW_DLL.dll se analiza mediante Autodesk AutoCAD se puede utilizar para variables no inicializadas. Esta vulnerabilidad, junto con otras vulnerabilidades, podría provocar la ejecución de código en el proceso actual.

22 Feb 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-22 05:15

Updated : 2024-03-18 00:15


NVD link : CVE-2024-23137

Mitre link : CVE-2024-23137

CVE.ORG link : CVE-2024-23137


JSON object : View

Products Affected

No product.

CWE
CWE-457

Use of Uninitialized Variable