First published: Tue Oct 07 2008(Updated: )
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via "..\" sequences in the argument to the SaveAS method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Design Review 2011 | =2009 | |
Autodesk Revit Architecture | =2009-sp2 | |
Autodesk DWF Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4471 is considered a critical vulnerability due to its potential to allow remote attackers to overwrite arbitrary files.
To mitigate CVE-2008-4471, users should update to the latest versions or patches provided by Autodesk for their software.
CVE-2008-4471 affects Autodesk Design Review 2009 and Autodesk Revit Architecture 2009 SP2.
CVE-2008-4471 is classified as a directory traversal vulnerability.
Yes, CVE-2008-4471 can be exploited remotely by sending specially crafted inputs to the affected ActiveX control.