Heap Overflow Vulnerability in Autodesk Navisworks Due to Malicious DWF Files
CVE-2024-12670
7.8HIGH
Key Information:
- Vendor
- Autodesk
- Vendor
- CVE Published:
- 17 December 2024
Summary
CVE-2024-12670 is a critical heap-based overflow vulnerability found in Autodesk Navisworks, specifically triggered by processing maliciously crafted DWF files. When exploited, this vulnerability allows an attacker to potentially execute arbitrary code, leading to crashes or unauthorized access to sensitive information in the context of the application. Users of affected Autodesk Navisworks versions are urged to apply security patches and adhere to best practices to mitigate the associated risks. Detailed information and remediation steps can be found in the Autodesk security advisory.
Affected Version(s)
Navisworks Freedom 2025 < 2025.4
Navisworks Manage 2025 < 2025.4
Navisworks Simulate 2025 < 2025.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved