CVE Vulnerabilities

CVE-2024-23137

Use of Uninitialized Variable

Published: Feb 22, 2024 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Weakness

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Affected Software

NameVendorStart VersionEnd Version
AutocadAutodesk2021 (including)2021.1.4 (excluding)
AutocadAutodesk2022 (including)2022.1.4 (excluding)
AutocadAutodesk2023 (including)2023.1.5 (excluding)
AutocadAutodesk2024 (including)2024.1.3 (excluding)
AutocadAutodesk2025 (including)2025.0.1 (excluding)

Potential Mitigations

References