CVE-2024-12178: DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
Published Dec 17, 2024
·Updated
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
2 affected components
Autodesk Navisworks
Autodesk Navisworks>=2025<2025.4
Event History
Dec 17, 2024
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12178?
CVE-2024-12178 is classified as a critical severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-12178?
To fix CVE-2024-12178, ensure that you update Autodesk Navisworks to the latest version provided by Autodesk.
3
What types of files exploit CVE-2024-12178?
CVE-2024-12178 is exploited through maliciously crafted DWFX files.
4
What can an attacker achieve with CVE-2024-12178?
An attacker can execute arbitrary code in the context of the current process by exploiting CVE-2024-12178.
5
What software is affected by CVE-2024-12178?
CVE-2024-12178 affects Autodesk Navisworks.