VendorsAutodeskautocad_advance_steelany version
Vulnerabilities

Autodesk AutoCAD Advance Steel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2023-29073
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published 2023-11-23 · Modified
9.8EPSS 0.011
CVE-2023-29074
A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published 2023-11-23 · Modified
9.8EPSS 0.011
CVE-2023-29075
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published 2023-11-23 · Modified
9.8EPSS 0.011
CVE-2023-29076
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
Published 2023-11-23 · Modified
9.8EPSS 0.011
CVE-2022-33886
A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.
Published 2022-10-03 · Modified
7.8EPSS 0.010
CVE-2022-33885
A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
Published 2022-10-03 · Modified
7.8EPSS 0.010
CVE-2021-40164
A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40163
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40166
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40165
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2021-40162
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
Published 2022-10-07 · Modified
7.8EPSS 0.009
CVE-2022-33890
A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Published 2022-10-03 · Modified
7.8EPSS 0.006
CVE-2022-33888
A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Published 2022-10-03 · Modified
7.8EPSS 0.006
CVE-2022-33887
A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.
Published 2022-10-03 · Modified
7.8EPSS 0.004
CVE-2022-33889
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.
Published 2022-10-03 · Modified
7.8EPSS 0.004
CVE-2023-29067
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Published 2023-04-14 · Modified
7.8EPSS 0.003
CVE-2023-41139
A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
Published 2023-11-23 · Modified
7.8EPSS 0.003
CVE-2023-41140
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published 2023-11-23 · Modified
7.8EPSS 0.003
CVE-2023-25003
A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.
Published 2023-06-23 · Modified
7.8EPSS 0.003
CVE-2023-27915
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Published 2023-04-14 · Modified
7.8EPSS 0.002
CVE-2023-27914
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.
Published 2023-04-14 · Modified
7.8EPSS 0.002
CVE-2023-27913
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data, or execute arbitrary code in the context of the current process.
Published 2023-04-14 · Modified
7.8EPSS 0.002
CVE-2023-29068
A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Published 2023-06-27 · Modified
7.8EPSS 0.002
CVE-2023-25004
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
Published 2023-06-27 · Modified
7.8EPSS 0.002
CVE-2023-27912
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.
Published 2023-04-14 · Modified
7.8EPSS 0.002
CVE-2024-8591
Autodesk AutoCAD 3DM File Parsing Heap-based Buffer Overflow Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8595
Autodesk AutoCAD MODEL File Parsing Use-After-Free Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-9826
Autodesk AutoCAD ACTranslators 3DM File Parsing Use-After-Free Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8590
Autodesk AutoCAD 3DM File Parsing Use-After-Free Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-7992
Autodesk AutoCAD DWG Stack-Based Buffer Overflow Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8592
Autodesk AutoCAD CATPART File Parsing Memory Corruption Code Execution Vulnerability
Published 2024-10-29 · Analyzed
7.8EPSS 0.002
CVE-2024-8593
Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8594
Autodesk AutoCAD MODEL File Parsing Heap-based Buffer Overflow Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8596
Autodesk AutoCAD MODEL File Parsing Out-Of-Bounds Write Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8597
Autodesk AutoCAD STEP File Parsing Memory Corruption Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8598
Autodesk AutoCAD ACTranslators STEP File Parsing Memory Corruption Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-9489
Autodesk AutoCAD DWG File Parsing Memory Corruption Code Execution Vulnerability
Published 2024-10-29 · Analyzed
7.8EPSS 0.002
CVE-2024-8600
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8599
Autodesk AutoCAD ACTranslators STP File Parsing Memory Corruption Code Execution Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-8589
Autodesk AutoCAD SLDPRT File Parsing Out-Of-Bounds Read Vulnerability
Published 2024-10-29 · Modified
7.8EPSS 0.002
1 / 2Next →