CVE-2024-12197: DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12197?
CVE-2024-12197 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-12197?
To mitigate CVE-2024-12197, users should update to the latest version of Autodesk Navisworks as recommended by the vendor.
What impact could CVE-2024-12197 have on my system?
Exploiting CVE-2024-12197 may cause crashes, data corruption, or allow an attacker to execute arbitrary code.
Which versions of Autodesk Navisworks are affected by CVE-2024-12197?
CVE-2024-12197 affects specific versions of Autodesk Navisworks, detailed in the vendor's security advisory.
Is there a workaround for CVE-2024-12197 if I cannot update Autodesk Navisworks?
Currently, the best course of action is to apply the update since no official workarounds have been provided for CVE-2024-12197.