CVE Vulnerabilities

CVE-2024-23141

Double Free

Published: Jun 25, 2024 | Modified: May 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Autocad Autodesk 2022 (including) 2022.1.5 (excluding)
Autocad Autodesk 2023 (including) 2023.1.6 (excluding)
Autocad Autodesk 2024 (including) 2024.1.4 (excluding)
Autocad Autodesk 2025 (including) 2025.1 (excluding)

Potential Mitigations

References