Heap Overflow Vulnerability in Autodesk Navisworks Due to Malicious DWF Files
CVE-2024-12670

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
17 December 2024

Summary

CVE-2024-12670 is a critical heap-based overflow vulnerability found in Autodesk Navisworks, specifically triggered by processing maliciously crafted DWF files. When exploited, this vulnerability allows an attacker to potentially execute arbitrary code, leading to crashes or unauthorized access to sensitive information in the context of the application. Users of affected Autodesk Navisworks versions are urged to apply security patches and adhere to best practices to mitigate the associated risks. Detailed information and remediation steps can be found in the Autodesk security advisory.

Affected Version(s)

Navisworks Freedom 2025 < 2025.4

Navisworks Manage 2025 < 2025.4

Navisworks Simulate 2025 < 2025.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-12670 : Heap Overflow Vulnerability in Autodesk Navisworks Due to Malicious DWF Files | SecurityVulnerability.io