CVE-2024-23137

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/02/2024
Last modified:
11/04/2025

Description

A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2021 (including) 2021.1.4 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2022 (including) 2022.1.4 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2023 (including) 2023.1.5 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2024 (including) 2024.1.3 (excluding)
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* 2025 (including) 2025.0.1 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2021 (including) 2021.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2022 (including) 2022.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2023 (including) 2023.1.5 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2024 (including) 2024.1.3 (excluding)
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* 2025 (including) 2025.0.1 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2021 (including) 2021.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2022 (including) 2022.1.4 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2023 (including) 2023.1.5 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2024 (including) 2024.1.3 (excluding)
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* 2025 (including) 2025.0.1 (excluding)