CRITICAL · 9.8

CVE-2023-29076

A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabil...

Vulnerability Description

A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AutodeskAutocad< 2024.1
AutodeskAutocad Advance Steel< 2023.1.4
AutodeskAutocad Architecture< 2023.1.4
AutodeskAutocad Civil 3D< 2023.1.4
AutodeskAutocad Electrical< 2023.1.4
AutodeskAutocad Lt< 2023.1.4
AutodeskAutocad Map 3D< 2023.1.4
AutodeskAutocad Mechanical< 2023.1.4
AutodeskAutocad Mep< 2023.1.4
AutodeskAutocad Plant 3D< 2023.1.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-29076?

CVE-2023-29076 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabil...

How severe is CVE-2023-29076?

CVE-2023-29076 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-29076?

Check the references section above for vendor advisories and patch information. Affected products include: Autodesk Autocad, Autodesk Autocad Advance Steel, Autodesk Autocad Architecture, Autodesk Autocad Civil 3D, Autodesk Autocad Electrical.