A maliciously crafted STP file when parsed in ASMDATAX230A.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
2024-10-29T22:15:07.703
2025-04-11T17:15:41.223
Modified
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | autodesk | autocad | < 2025.1.1 | Yes |
| Application | autodesk | autocad_advance_steel | < 2025.1.1 | Yes |
| Application | autodesk | autocad_architecture | < 2025.1.1 | Yes |
| Application | autodesk | autocad_civil_3d | < 2025.1.1 | Yes |
| Application | autodesk | autocad_electrical | < 2025.1.1 | Yes |
| Application | autodesk | autocad_mechanical | < 2025.1.1 | Yes |
| Application | autodesk | autocad_mep | < 2025.1.1 | Yes |
| Application | autodesk | autocad_plant_3d | < 2025.1.1 | Yes |
| Operating System | microsoft | windows | - | No |