CVE-2024-12670

A maliciously crafted DWF file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*

History

08 May 2025, 15:31

Type Values Removed Values Added
CWE CWE-787
First Time Autodesk navisworks
Autodesk
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027 - Vendor Advisory
CPE cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*

29 Jan 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Un archivo DWF manipulado con fines malintencionados, cuando se analiza a través de Autodesk Navisworks, se puede utilizar para provocar una vulnerabilidad de desbordamiento basado en el montón. Un actor malintencionado puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar código arbitrario en el contexto del proceso actual.
References
  • {'url': 'https://autodesk.com/trust/security-advisories/adsk-sa-2024-0027', 'source': 'psirt@autodesk.com'}
  • () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0027 -

17 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-17 16:15

Updated : 2025-05-08 15:31


NVD link : CVE-2024-12670

Mitre link : CVE-2024-12670

CVE.ORG link : CVE-2024-12670


JSON object : View

Products Affected

autodesk

  • navisworks
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write