cve/2024/CVE-2024-23136.md

19 lines
867 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2024-23136](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23136)
![](https://img.shields.io/static/v1?label=Product&message=AutoCAD%2C%20Advance%20Steel%20and%20Civil%203D&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%202024%2C%202023%2C%202022%2C%202021%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-822%3A%20Untrusted%20Pointer%20Dereference&color=brighgreen)
### Description
A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk AutoCAD can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/NaInSec/CVE-LIST
- https://github.com/fkie-cad/nvd-json-data-feeds