CVE-2024-7672

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 30, 2024
Updated: Feb 10, 2025
CWE ID 787

Summary

CVE-2024-7672 is a newly disclosed vulnerability affecting Autodesk Navisworks. A specially crafted DWF file can trigger an Out-of-Bounds Write vulnerability in dwfcore.dll. This issue may lead to a crash, data corruption, or even the execution of arbitrary code in the current process. Malicious actors can exploit this vulnerability by persuading users to open the malicious DWF file. Autodesk is encouraged to release a patch to address this issue and mitigate potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Autodesk Navisworks
  • Navisworks Freedom

Affected Vendors

  • Autodesk