A
maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
References
| Link | Resource |
|---|---|
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory |
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 | Vendor Advisory |
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
History
11 Apr 2025, 15:55
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* |
|
| First Time |
Autodesk autocad Mep
Autodesk autocad Autodesk Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Architecture Autodesk advance Steel Autodesk autocad Electrical Autodesk civil 3d Autodesk autocad Plant 3d |
|
| CWE | NVD-CWE-Other | |
| References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 - Vendor Advisory | |
| References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 - Vendor Advisory |
27 Jan 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| Summary | (en) A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. |
21 Nov 2024, 08:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0002 - | |
| References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0004 - |
01 Aug 2024, 13:47
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Information
Published : 2024-02-22 05:15
Updated : 2025-12-31 00:41
NVD link : CVE-2024-23136
Mitre link : CVE-2024-23136
CVE.ORG link : CVE-2024-23136
JSON object : View
Products Affected
CWE