CVE-2024-8587 describes a Heap Based Buffer Overflow vulnerability in Autodesk AutoCAD and related products, triggered by parsing a maliciously crafted SLDPRT file. This vulnerability carries a high CVSS score of 7.8 due to its low attack complexity and potential for significant impact, including crashes, sensitive data writing, or arbitrary code execution. While user interaction is required (UI:R), the attack vector is local (AV:L). Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not widely known or exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2025CPE matchmatch criteria | cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:* | ||
2025CPE matchmatch criteria | cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:* | ||
2025CPE matchmatch criteria | cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:* | ||
2025CPE matchmatch criteria | cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:* | ||
2025CPE matchmatch criteria | cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.