CVE-2024-23147
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
25/06/2024
Last modified:
22/01/2026
Description
A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* | 2022 (including) | 2022.1.5 (excluding) |
| cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* | 2023 (including) | 2023.1.6 (excluding) |
| cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* | 2024 (including) | 2024.1.4 (excluding) |
| cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* | 2025 (including) | 2025.1 (excluding) |
| cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* | 2022 (including) | 2022.1.5 (excluding) |
| cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* | 2023 (including) | 2023.1.6 (excluding) |
| cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* | 2024 (including) | 2024.1.4 (excluding) |
| cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* | 2025 (including) | 2025.1 (excluding) |
| cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* | 2022 (including) | 2022.1.5 (excluding) |
| cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* | 2023 (including) | 2023.1.6 (excluding) |
| cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* | 2024 (including) | 2024.1.4 (excluding) |
| cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* | 2025 (including) | 2025.1 (excluding) |
| cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* | 2022 (including) | 2022.1.5 (excluding) |
| cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* | 2023 (including) | 2023.1.6 (excluding) |
| cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* | 2024 (including) | 2024.1.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



