CVE-2024-7675
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Sep 30, 2024
Updated: Jan 29, 2025
CWE ID 416
Summary
CVE-2024-7675 is a newly identified vulnerability that affects the Autodesk Navisworks software. A specially crafted DWF file can trigger a Use-After-Free condition in w3dtk.dll. This issue allows a malicious actor to cause a crash or execute arbitrary code with the privileges of the current process. Successful exploitation of this vulnerability can lead to significant security implications for organizations using Autodesk Navisworks. It is recommended that users apply the necessary patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Autodesk Navisworks
- Navisworks Freedom
Affected Vendors
- Autodesk