VYPR
Unrated severityNVD Advisory· Published Feb 22, 2024· Updated Aug 26, 2025

Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software

CVE-2024-23136

Description

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Affected products

9
  • Autodesk/Advance Steelv5
    cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
    Range: 2025
  • cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/AutoCAD Architecturev5
    cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/AutoCAD Electricalv5
    cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/AutoCAD MAP 3Dv5
    cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/AutoCAD Mechanicalv5
    cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/AutoCAD MEPv5
    cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/AutoCAD Plant 3Dv5
    cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
    Range: 2025
  • Autodesk/Civil 3Dv5
    cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
    Range: 2025

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.