CVE-2023-25001: Use After Free
Published Jun 27, 2023
·Updated
A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Affected Software
2 affected components
Autodesk Navisworks=2022
Autodesk Navisworks=2023
Event History
Jun 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-25001?
CVE-2023-25001 is a vulnerability in Autodesk Navisworks 2023 and 2022 that can be triggered by a maliciously crafted SKP file, leading to a use-after-free vulnerability and potential code execution.
2
How severe is CVE-2023-25001?
CVE-2023-25001 has a severity rating of 7.8, which is considered high.
3
Which versions of Autodesk Navisworks are affected by CVE-2023-25001?
CVE-2023-25001 affects Autodesk Navisworks 2023 and 2022.
4
How can CVE-2023-25001 be exploited?
CVE-2023-25001 can be exploited by using a maliciously crafted SKP file.
5
What is the potential impact of CVE-2023-25001?
Exploitation of CVE-2023-25001 can result in code execution.