CVE-2024-7675

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 30, 2024
Updated: Jan 29, 2025
CWE ID 416

Summary

CVE-2024-7675 is a newly identified vulnerability that affects the Autodesk Navisworks software. A specially crafted DWF file can trigger a Use-After-Free condition in w3dtk.dll. This issue allows a malicious actor to cause a crash or execute arbitrary code with the privileges of the current process. Successful exploitation of this vulnerability can lead to significant security implications for organizations using Autodesk Navisworks. It is recommended that users apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Autodesk Navisworks
  • Navisworks Freedom

Affected Vendors

  • Autodesk