CVE-2024-12194: DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
Published Dec 17, 2024
·Updated
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
2 affected components
Autodesk Navisworks
Autodesk Navisworks>=2025<2025.4
Event History
Dec 17, 2024
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12194?
CVE-2024-12194 has a high severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-12194?
To fix CVE-2024-12194, update Autodesk Navisworks to the latest version provided by Autodesk.
3
What is the impact of CVE-2024-12194?
The impact of CVE-2024-12194 allows a malicious actor to execute arbitrary code, leading to possible full system compromise.
4
Which software is affected by CVE-2024-12194?
CVE-2024-12194 affects Autodesk Navisworks when handling maliciously crafted DWFX files.
5
What type of vulnerability is CVE-2024-12194?
CVE-2024-12194 is a memory corruption vulnerability that can be exploited through specially crafted files.