A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
2024-03-18T00:15:07.587
2025-12-31T00:41:24.293
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | autodesk | advance_steel | < 2021.1.4 | Yes |
| Application | autodesk | advance_steel | < 2022.1.4 | Yes |
| Application | autodesk | advance_steel | < 2023.1.5 | Yes |
| Application | autodesk | advance_steel | < 2024.1.3 | Yes |
| Application | autodesk | autocad | < 2021.1.4 | Yes |
| Application | autodesk | autocad | < 2022.1.4 | Yes |
| Application | autodesk | autocad | < 2022.4.1 | Yes |
| Application | autodesk | autocad | < 2023.1.5 | Yes |
| Application | autodesk | autocad | < 2023.3.1 | Yes |
| Application | autodesk | autocad | < 2024.1.2 | Yes |
| Application | autodesk | autocad | < 2024.1.3 | Yes |
| Application | autodesk | autocad_architecture | < 2021.1.4 | Yes |
| Application | autodesk | autocad_architecture | < 2022.1.4 | Yes |
| Application | autodesk | autocad_architecture | ≤ 2023.1.5 | Yes |
| Application | autodesk | autocad_architecture | < 2024.1.3 | Yes |
| Application | autodesk | autocad_electrical | < 2021.1.4 | Yes |
| Application | autodesk | autocad_electrical | < 2022.1.4 | Yes |
| Application | autodesk | autocad_electrical | < 2023.1.5 | Yes |
| Application | autodesk | autocad_electrical | < 2024.1.3 | Yes |
| Application | autodesk | autocad_lt | < 2021.1.4 | Yes |
| Application | autodesk | autocad_lt | < 2022.1.4 | Yes |
| Application | autodesk | autocad_lt | < 2022.4.1 | Yes |
| Application | autodesk | autocad_lt | < 2023.1.5 | Yes |
| Application | autodesk | autocad_lt | < 2023.3.1 | Yes |
| Application | autodesk | autocad_lt | < 2024.1.2 | Yes |
| Application | autodesk | autocad_lt | < 2024.1.3 | Yes |
| Application | autodesk | autocad_map_3d | < 2021.1.4 | Yes |
| Application | autodesk | autocad_map_3d | < 2022.1.4 | Yes |
| Application | autodesk | autocad_map_3d | < 2023.1.5 | Yes |
| Application | autodesk | autocad_map_3d | < 2024.1.3 | Yes |
| Application | autodesk | autocad_mechanical | < 2021.1.4 | Yes |
| Application | autodesk | autocad_mechanical | < 2022.1.4 | Yes |
| Application | autodesk | autocad_mechanical | < 2023.1.5 | Yes |
| Application | autodesk | autocad_mechanical | < 2024.1.3 | Yes |
| Application | autodesk | autocad_mep | < 2021.1.4 | Yes |
| Application | autodesk | autocad_mep | < 2022.1.4 | Yes |
| Application | autodesk | autocad_mep | < 2023.15 | Yes |
| Application | autodesk | autocad_mep | < 2024.1.3 | Yes |
| Application | autodesk | autocad_plant_3d | < 2021.1.4 | Yes |
| Application | autodesk | autocad_plant_3d | < 2022.1.4 | Yes |
| Application | autodesk | autocad_plant_3d | < 2023.1.5 | Yes |
| Application | autodesk | autocad_plant_3d | < 2024.1.3 | Yes |
| Application | autodesk | civil_3d | < 2021.1.4 | Yes |
| Application | autodesk | civil_3d | < 2022.1.4 | Yes |
| Application | autodesk | civil_3d | < 2023.1.5 | Yes |
| Application | autodesk | civil_3d | < 2024.1.3 | Yes |
| Application | autodesk | dwg_trueview | < 2022.1.4 | Yes |
| Application | autodesk | dwg_trueview | < 2023.1.5 | Yes |
| Application | autodesk | dwg_trueview | < 2024.1.3 | Yes |