← Vulnerability feed

Vulnerability record · CVE-2023-29073 · published 23 November 2023

CVE-2023-29073: Autodesk autocad heap-based buffer overflow vulnerability

Autodesk · Autocad

A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

9.8 CVSS 3.1 Critical EPSS 1.1% · top 35.0% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29073 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29074Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor …EPSS 1.1%9.8CVE-2023-29075Autodesk autocad out-of-bounds write vulnerabilityA maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can …EPSS 1.1%9.8CVE-2023-29076Autodesk autocad memory buffer overflow vulnerabilityA maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabili…EPSS 1.1%7.8CVE-2026-7406Autodesk advance steel vulnerabilityA maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious a…EPSS 0.19%7.8CVE-2026-16463Autodesk advance steel heap-based buffer overflow vulnerabilityA maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…EPSS 0.28%7.8CVE-2025-8893Autodesk revit out-of-bounds write vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may …EPSS 0.17%7.8CVE-2025-8894Autodesk autocad plant 3d heap-based buffer overflow vulnerabilityA maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can l…EPSS 0.17%7.8CVE-2025-5047Autodesk advance steel vulnerabilityA maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can levera…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2023-29073), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.