A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 26 Aug 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Autodesk aautocad Lt Autodesk autocad Lt For Mac Autodesk autocad Mac Autodesk autocad Mechnaical | |
| CPEs | cpe:2.3:a:autodesk:aautocad_lt:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt_for_mac:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt_for_mac:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt_for_mac:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mac:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mac:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mac:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechnaical:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:dwg_trueview:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:* | |
| Vendors & Products | Autodesk aautocad Lt Autodesk autocad Lt For Mac Autodesk autocad Mac Autodesk autocad Mechnaical | 
Tue, 29 Jul 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Autodesk advance Steel Autodesk autocad Lt Autodesk civil 3d Autodesk dwg Trueview | |
| CPEs | cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:macos:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:macos:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:* | |
| Vendors & Products | Autodesk advance Steel Autodesk autocad Lt Autodesk civil 3d Autodesk dwg Trueview | 
Wed, 29 Jan 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Autodesk Autodesk autocad Autodesk autocad Advance Steel Autodesk autocad Architecture Autodesk autocad Civil 3d Autodesk autocad Electrical Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d | |
| CPEs | cpe:2.3:a:autodesk:autocad:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_advance_steel:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_civil_3d:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:2021:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:2022:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:* | |
| Vendors & Products | Autodesk Autodesk autocad Autodesk autocad Advance Steel Autodesk autocad Architecture Autodesk autocad Civil 3d Autodesk autocad Electrical Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d | |
| Metrics | ssvc 
 | 
Tue, 28 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | 
| Title | Stack-based Overflow Vulnerability in the TrueViewTM Desktop Software | |
| Metrics | cvssV3_1 
 | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: autodesk
Published: 2024-03-17T23:56:39.590Z
Updated: 2025-08-26T20:39:55.954Z
Reserved: 2024-01-11T21:47:40.857Z
Link: CVE-2024-23138
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T22:59:30.676Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-03-18T00:15:07.587
Modified: 2025-08-26T21:15:40.713
Link: CVE-2024-23138
 Redhat
                        Redhat
                    No data.