CVE-2024-23131
Last modified
CVE-2024-23131 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Autodesk | Autocad Electrical | >= 2021, < 2021.1.4 |
| Autodesk | Autocad Electrical | >= 2022, < 2022.1.4 |
| Autodesk | Autocad Electrical | >= 2023, < 2023.1.5 |
| Autodesk | Autocad Electrical | >= 2024, < 2024.1.3 |
| Autodesk | Autocad Electrical | >= 2025, < 2025.0.1 |
| Autodesk | Autocad Mechanical | >= 2021, < 2021.1.4 |
| Autodesk | Autocad Mechanical | >= 2022, < 2022.1.4 |
| Autodesk | Autocad Mechanical | >= 2023, < 2023.1.5 |
| Autodesk | Autocad Mechanical | >= 2024, < 2024.1.3 |
| Autodesk | Autocad Mechanical | >= 2025, < 2025.0.1 |
| Autodesk | Autocad Mep | >= 2021, < 2021.1.4 |
| Autodesk | Autocad Mep | >= 2022, < 2022.1.4 |
| Autodesk | Autocad Mep | >= 2023, < 2023.1.5 |
| Autodesk | Autocad Mep | >= 2024, < 2024.1.3 |
| Autodesk | Autocad Mep | >= 2025, < 2025.0.1 |
| Autodesk | Autocad Plant 3d | >= 2021, < 2021.1.4 |
| Autodesk | Autocad Plant 3d | >= 2022, < 2022.1.4 |
| Autodesk | Autocad Plant 3d | >= 2023, < 2023.1.5 |
| Autodesk | Autocad Plant 3d | >= 2024, < 2024.1.3 |
| Autodesk | Autocad Plant 3d | >= 2025, < 2025.0.1 |
| Autodesk | Civil 3d | >= 2021, < 2021.1.4 |
| Autodesk | Civil 3d | >= 2022, < 2022.1.4 |
| Autodesk | Civil 3d | >= 2023, < 2023.1.5 |
| Autodesk | Civil 3d | >= 2024, < 2024.1.3 |
| Autodesk | Civil 3d | >= 2025, < 2025.0.1 |
| Autodesk | Advance Steel | >= 2021, < 2021.1.4 |
| Autodesk | Advance Steel | >= 2022, < 2022.1.4 |
| Autodesk | Advance Steel | >= 2023, < 2023.1.5 |
| Autodesk | Advance Steel | >= 2024, < 2024.1.3 |
| Autodesk | Advance Steel | >= 2025, < 2025.0.1 |
| Autodesk | Autocad Map 3d | >= 2021, < 2021.1.4 |
| Autodesk | Autocad Map 3d | >= 2022, < 2022.1.4 |
| Autodesk | Autocad Map 3d | >= 2023, < 2023.1.5 |
| Autodesk | Autocad Map 3d | >= 2024, < 2024.1.3 |
| Autodesk | Autocad Map 3d | >= 2025, < 2025.0.1 |
| Autodesk | Autocad | >= 2021, < 2021.1.4 |
| Autodesk | Autocad | >= 2022, < 2022.1.4 |
| Autodesk | Autocad | >= 2023, < 2023.1.5 |
| Autodesk | Autocad | >= 2024, < 2024.1.3 |
| Autodesk | Autocad | >= 2025, < 2025.0.1 |
| Autodesk | Autocad Architecture | >= 2021, < 2021.1.4 |
| Autodesk | Autocad Architecture | >= 2022, < 2022.1.4 |
| Autodesk | Autocad Architecture | >= 2023, < 2023.1.5 |
| Autodesk | Autocad Architecture | >= 2024, < 2024.1.3 |
| Autodesk | Autocad Architecture | >= 2025, < 2025.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-23131?
How severe is CVE-2024-23131?
How do I fix CVE-2024-23131?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-23126A maliciously crafted CATPART file when parsed CC5Dll.dll th…7.8
- CVE-2024-23127A maliciously crafted MODEL, SLDPRT, or SLDASM file, when pa…7.8
- CVE-2024-23128A maliciously crafted MODEL file, when parsed in libodxdll.d…7.8
- CVE-2024-23129A maliciously crafted MODEL 3DM, STP, or SLDASM file, when i…7.8
- CVE-2024-2313If kernel headers need to be extracted, bpftrace will attemp…2.8
- CVE-2024-23130A maliciously crafted SLDASM or SLDPRT file, when parsed in …7.8
- CVE-2024-23132A maliciously crafted STP file in atf_dwg_consumer.dll when …7.8
- CVE-2024-23133A maliciously crafted STP file in ASMDATAX228A.dll when pars…7.8
- CVE-2024-23134A maliciously crafted IGS file in tbb.dll when parsed throug…7.8
- CVE-2024-23135A maliciously crafted SLDPRT file in ASMkern228A.dll when pa…7.8
- CVE-2024-23136A maliciously crafted STP file in ASMKERN228A.dll when parse…7.8
- CVE-2024-23137A maliciously crafted STP or SLDPRT file, when parsed in ODX…7.8
Are you affected by CVE-2024-23131?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
