CVE-2024-9827

A maliciously crafted CATPART file when parsed in CC5Dll.dll through Autodesk AutoCAD can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

01 Nov 2024, 16:17

Type Values Removed Values Added
First Time Autodesk autocad Plant 3d
Autodesk autocad Advance Steel
Autodesk autocad
Autodesk autocad Architecture
Autodesk autocad Civil 3d
Autodesk autocad Mechanical
Autodesk autocad Mep
Autodesk
Autodesk autocad Electrical
Microsoft
Microsoft windows
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0019 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0019 - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*

01 Nov 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Un archivo CATPART creado con fines malintencionados, cuando se analiza en CC5Dll.dll a través de Autodesk AutoCAD, puede provocar una vulnerabilidad de lectura fuera de los límites. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar código arbitrario en el contexto del proceso actual.

29 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-29 22:15

Updated : 2024-11-01 16:17


NVD link : CVE-2024-9827

Mitre link : CVE-2024-9827

CVE.ORG link : CVE-2024-9827


JSON object : View

Products Affected

microsoft

  • windows

autodesk

  • autocad_electrical
  • autocad_advance_steel
  • autocad
  • autocad_mechanical
  • autocad_mep
  • autocad_plant_3d
  • autocad_civil_3d
  • autocad_architecture
CWE
CWE-125

Out-of-bounds Read