A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
2024-10-29T22:15:08.513
2024-11-01T16:27:16.693
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | autodesk | autocad | < 2025.1.1 | Yes |
| Application | autodesk | autocad_advance_steel | < 2025.1.1 | Yes |
| Application | autodesk | autocad_architecture | < 2025.1.1 | Yes |
| Application | autodesk | autocad_civil_3d | < 2025.1.1 | Yes |
| Application | autodesk | autocad_electrical | < 2025.1.1 | Yes |
| Application | autodesk | autocad_lt | < 2025.1.1 | Yes |
| Application | autodesk | autocad_mechanical | < 2025.1.1 | Yes |
| Application | autodesk | autocad_mep | < 2025.1.1 | Yes |
| Application | autodesk | autocad_plant_3d | < 2025.1.1 | Yes |
| Application | autodesk | dwg_trueview | < 2025.1.1 | Yes |