CVE-2024-12194

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*

History

08 May 2025, 15:14

Type Values Removed Values Added
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027 - Vendor Advisory
CPE cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*
First Time Autodesk navisworks
Autodesk
CWE CWE-787

29 Jan 2025, 17:15

Type Values Removed Values Added
References
  • {'url': 'https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027', 'source': 'psirt@autodesk.com'}
  • () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027 -
Summary
  • (es) Un archivo DWFX manipulado con fines malintencionados, al analizarse mediante Autodesk Navisworks, puede provocar una vulnerabilidad de corrupción de memoria. Un actor malintencionado puede aprovechar esta vulnerabilidad para ejecutar código arbitrario en el contexto del proceso actual.

17 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-17 16:15

Updated : 2025-05-08 15:14


NVD link : CVE-2024-12194

Mitre link : CVE-2024-12194

CVE.ORG link : CVE-2024-12194


JSON object : View

Products Affected

autodesk

  • navisworks
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-787

Out-of-bounds Write