A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 9
Known Affected Software Configurations 36
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Autodesk Autocad
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Advance_Steel
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Advance_Steel
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Advance_Steel
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Advance_Steel
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Civil_3d
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Civil_3d
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Civil_3d
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Civil_3d
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Autocad_Mechanical
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad_Mechanical
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad_Mechanical
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad_Mechanical
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Autocad_Mep
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad_Mep
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad_Mep
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad_Mep
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Autocad_Plant_3d
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad_Plant_3d
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad_Plant_3d
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad_Plant_3d
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Autocad_Map_3d
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad_Map_3d
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad_Map_3d
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad_Map_3d
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Autocad_Architecture
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad_Architecture
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad_Architecture
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad_Architecture
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|
|
Autodesk Autocad_Electrical
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
|
2022
|
2022.1.6
|
|
Autodesk Autocad_Electrical
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
|
2023
|
2023.1.7
|
|
Autodesk Autocad_Electrical
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
|
2024
|
2024.1.7
|
|
Autodesk Autocad_Electrical
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
|
2025
|
2025.1.2
|