Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23136


A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.


Published

2024-02-22T05:15:09.527

Last Modified

2025-12-31T00:41:19.613

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-822
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application autodesk autocad_electrical < 2021.1.4 Yes
Application autodesk autocad_electrical < 2022.1.4 Yes
Application autodesk autocad_electrical < 2023.1.5 Yes
Application autodesk autocad_electrical < 2024.1.3 Yes
Application autodesk autocad_electrical < 2025.0.1 Yes
Application autodesk autocad_mechanical < 2021.1.4 Yes
Application autodesk autocad_mechanical < 2022.1.4 Yes
Application autodesk autocad_mechanical < 2023.1.5 Yes
Application autodesk autocad_mechanical < 2024.1.3 Yes
Application autodesk autocad_mechanical < 2025.0.1 Yes
Application autodesk autocad_mep < 2021.1.4 Yes
Application autodesk autocad_mep < 2022.1.4 Yes
Application autodesk autocad_mep < 2023.1.5 Yes
Application autodesk autocad_mep < 2024.1.3 Yes
Application autodesk autocad_mep < 2025.0.1 Yes
Application autodesk autocad_plant_3d < 2021.1.4 Yes
Application autodesk autocad_plant_3d < 2022.1.4 Yes
Application autodesk autocad_plant_3d < 2023.1.5 Yes
Application autodesk autocad_plant_3d < 2024.1.3 Yes
Application autodesk autocad_plant_3d < 2025.0.1 Yes
Application autodesk civil_3d < 2021.1.4 Yes
Application autodesk civil_3d < 2022.1.4 Yes
Application autodesk civil_3d < 2023.1.5 Yes
Application autodesk civil_3d < 2024.1.3 Yes
Application autodesk civil_3d < 2025.0.1 Yes
Application autodesk advance_steel < 2021.1.4 Yes
Application autodesk advance_steel < 2022.1.4 Yes
Application autodesk advance_steel < 2023.1.5 Yes
Application autodesk advance_steel < 2024.1.3 Yes
Application autodesk advance_steel < 2025.0.1 Yes
Application autodesk autocad_map_3d < 2021.1.4 Yes
Application autodesk autocad_map_3d < 2022.1.4 Yes
Application autodesk autocad_map_3d < 2023.1.5 Yes
Application autodesk autocad_map_3d < 2024.1.3 Yes
Application autodesk autocad_map_3d < 2025.0.1 Yes
Application autodesk autocad < 2021.1.4 Yes
Application autodesk autocad < 2022.1.4 Yes
Application autodesk autocad < 2023.1.5 Yes
Application autodesk autocad < 2024.1.3 Yes
Application autodesk autocad < 2025.0.1 Yes
Application autodesk autocad_architecture < 2021.1.4 Yes
Application autodesk autocad_architecture < 2022.1.4 Yes
Application autodesk autocad_architecture < 2023.1.5 Yes
Application autodesk autocad_architecture < 2024.1.3 Yes
Application autodesk autocad_architecture < 2025.0.1 Yes

References