CVE-2023-41139High· 7.8▾ TwilightA maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
autocad < 2024.1autocad >= 2023.0.0, < 2023.1.4autocad >= 2024.0.0, < 2024.1.1autocad_advance_steel < 2023.1.4autocad_advance_steel >= 2024.0.0, < 2024.1.1autocad_architecture < 2023.1.4autocad_architecture >= 2024.0.0, < 2024.1.1autocad_civil_3d < 2023.1.4autocad_civil_3d >= 2024.0.0, < 2024.1.1autocad_electrical < 2023.1.4autocad_electrical >= 2024.0.0, < 2024.1.1autocad_lt < 2023.1.4autocad_lt < 2024.1autocad_lt >= 2024.0.0, < 2024.1.1autocad_map_3d < 2023.1.4autocad_map_3d >= 2024.0.0, < 2024.1.1autocad_mechanical < 2023.1.4autocad_mechanical >= 2024.0.0, < 2024.1.1autocad_mep < 2023.1.4autocad_mep >= 2024.0.0, < 2024.1.1autocad_plant_3d < 2023.1.4autocad_plant_3d >= 2024.0.0, < 2024.1.1Upgrade past the affected range:
autocad 2024.1.1autocad_advance_steel 2024.1.1autocad_architecture 2024.1.1autocad_civil_3d 2024.1.1autocad_electrical 2024.1.1autocad_lt 2024.1.1autocad_map_3d 2024.1.1autocad_mechanical 2024.1.1autocad_mep 2024.1.1autocad_plant_3d 2024.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2022-27867High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability
CVE-2026-7406High· 7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability
CVE-2015-2546High· 8.2The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privile…
CVE-2020-3562High· 8.6A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affec…
CVE-2024-30090High· 7.0Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2022-25788High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files