Stack-based buffer overflow in Autodesk products - CVE-2024-23138
Published: April 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the parsing of DWG files. A remote unauthenticated attacker can trick a victim to open a specially crafted file, trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
AutoCAD Mechanical
AutoCAD Map 3D
AutoCAD MEP
AutoCAD Plant 3D
AutoCAD Electrical
AutoCAD Architecture
Advance Steel
AutoCAD LT
DWG Trueview
AutoCAD Mac
AutoCAD for Mac LT
Autodesk AutoCAD
How to mitigate CVE-2024-23138
AutoCAD Mechanical - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD Map 3D - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD MEP - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD Plant 3D - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD Electrical - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD Architecture - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
Advance Steel - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
Autodesk AutoCAD - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD LT - addressed in versions 2021.1.4, 2022.1.4, 2023.1.5, 2024.1.3
DWG Trueview - addressed in versions 2022.1.4, 2023.1.5, 2024.1.3
AutoCAD Mac - update to 2023.3.1
AutoCAD for Mac LT - update to 2023.3.1