cve/2024/CVE-2024-23127.md
2024-05-25 21:48:12 +02:00

927 B

CVE-2024-23127

Description

A maliciously crafted MODEL, SLDPRT or SLDASM file in VCRUNTIME140.dll when parsed through Autodesk AutoCAD can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

POC

Reference

No PoCs from references.

Github