CVE-2024-23159

June 25, 2024, 12:24 p.m.

Product(s) Impacted

Autodesk applications

Description

A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Weaknesses

CWE-457
Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

CWE ID: 457

Date

Published: June 25, 2024, 4:15 a.m.

Last Modified: June 25, 2024, 12:24 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

psirt@autodesk.com

References