CVE-2024-9489

A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*

History

01 Nov 2024, 16:27

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0021 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0021 - Vendor Advisory
First Time Autodesk dwg Trueview
Autodesk autocad Lt
Autodesk autocad Plant 3d
Autodesk autocad Advance Steel
Autodesk autocad
Autodesk autocad Architecture
Autodesk autocad Civil 3d
Autodesk autocad Mechanical
Autodesk autocad Mep
Autodesk
Autodesk autocad Electrical
CWE CWE-787

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Un archivo DWG creado con fines malintencionados, al analizarse en ACAD.exe a través de Autodesk AutoCAD, puede provocar una vulnerabilidad de corrupción de memoria. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, escribir datos confidenciales o ejecutar código arbitrario en el contexto del proceso actual.

29 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 22:15

Updated : 2024-11-01 16:27


NVD link : CVE-2024-9489

Mitre link : CVE-2024-9489

CVE.ORG link : CVE-2024-9489


JSON object : View

Products Affected

autodesk

  • autocad_lt
  • autocad_electrical
  • autocad_advance_steel
  • autocad
  • autocad_mechanical
  • autocad_mep
  • autocad_plant_3d
  • dwg_trueview
  • autocad_civil_3d
  • autocad_architecture
CWE
CWE-787

Out-of-bounds Write

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer