Autodesk Revit Vulnerability Allows Stack-Based Buffer Overflow
CVE-2024-7994

7.8HIGH

Key Information:

Vendor
Autodesk
Status
Vendor
CVE Published:
16 October 2024

Summary

A vulnerability exists in Autodesk Revit which can be exploited by processing a specially crafted RFA file. This vulnerability enables a stack-based buffer overflow, allowing malicious actors to crash the application or read sensitive information. Additionally, it can facilitate the execution of arbitrary code within the current process context, posing significant security risks to users. Affected versions include Autodesk Revit 2021 through 2024.

Affected Version(s)

Revit 2025 < 2025.3

Revit 2024 < 2024.3

Revit 2023 < 2023.1.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.