October 2024 - Autodesk AutoCAD Security Vulnerabilities
Autodesk AutoCAD is a widely-used platform for 3D design and CAD software. However, CVEs published on October 29, 2024, have revealed that maliciously crafted files can create significant security vulnerabilities within AutoCAD. In this article, we will examine the critical security vulnerabilities affecting Autodesk AutoCAD.
CVE-2024-9827: Out-of-Bounds Read Vulnerability in Autodesk AutoCAD
A malicious CATPART file can lead to an Out-of-Bounds Read vulnerability during the processing of the CC5Dll.dll file in Autodesk AutoCAD. This vulnerability could allow an attacker to crash the system, read sensitive data, or execute arbitrary code within the current process context.
- Published Date: October 29, 2024
- CVSS Score: 7.8 HIGH
- Characteristics: Out-of-b
CVE-2024-9826: Use-After-Free Vulnerability in Autodesk AutoCAD
A malicious 3DM file can trigger a Use-After-Free vulnerability during the processing of the atf_api.dll file in AutoCAD. This vulnerability allows attackers to cause a system crash, write sensitive data, or execute arbitrary code within the current process context.
- Published Date: October 29, 2024
- CVSS Score: 7.8 HIGH
- Characteristics: Access after use weakens memory security, potentially resulting in unauthorized access to sensitive information.
CVE-2024-8600: Memory Corruption Vulnerability in Autodesk AutoCAD
A malicious SLDPRT file can lead to a Memory Corruption vulnerability during the processing of the odxsw_dll.dll file in Autodesk AutoCAD. This vulnerability allows attackers to crash the system or manipulate sensitive data within the process context.
- Published Date: October 29, 2024
- CVSS Score: 7.8 HIGH
- Characteristics: Memory corruption can affect system stability and enable arbitrary code execution.
CVE-2024-8599: Memory Corruption Vulnerability in Autodesk AutoCAD
A malicious STP file can cause memory corruption during the processing of the ACTranslators.exe file in AutoCAD, allowing attackers to write data or execute code.
- Published Date: October 29, 2024
- CVSS Score: 7.8 HIGH
- Characteristics: Memory corruption compromises data security, allowing unauthorized writing of sensitive information.
CVE-2024-8598: Memory Corruption Vulnerability in Autodesk AutoCAD
A malicious STP file in the ACTranslators.exe file can lead to memory corruption. This vulnerability enables attackers to crash the system or manipulate data within the process context.
- Published Date: October 29, 2024
- CVSS Score: 7.8 HIGH
- Characteristics: Memory corruption impacts data security, enabling unauthorized access to sensitive information.
CVE-2024-8597: Memory Corruption Vulnerability in Autodesk AutoCAD
A Memory Corruption vulnerability may arise when an STP file is processed in the ASMDATAX230A.dll file in AutoCAD, allowing attackers to damage the system or alter sensitive data.
- Published Date: October 29, 2024
- CVSS Score: 7.8 HIGH
- Characteristics: Memory corruption may lead to system crashes and data manipulation.