Unrated severityNVD Advisory· Published Feb 22, 2024· Updated Aug 26, 2025
Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
CVE-2024-23136
Description
A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
Affected products
9- Autodesk/Advance Steelv5cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/AutoCAD Architecturev5cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/AutoCAD Electricalv5cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/AutoCAD MAP 3Dv5cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/AutoCAD Mechanicalv5cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/AutoCAD MEPv5cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/AutoCAD Plant 3Dv5cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*Range: 2025
- Autodesk/Civil 3Dv5cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*Range: 2025
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.