CVE-2024-12669: DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12669?
CVE-2024-12669 is classified as a high severity vulnerability due to its potential to cause a heap-based overflow.
What type of attack can exploit CVE-2024-12669?
CVE-2024-12669 can be exploited through a maliciously crafted DWFX file to cause crashes, read sensitive data, or execute arbitrary code.
How do I fix CVE-2024-12669?
To mitigate CVE-2024-12669, ensure that you update your Autodesk Navisworks to the latest version provided by Autodesk.
Which versions of Autodesk Navisworks are affected by CVE-2024-12669?
CVE-2024-12669 affects all versions of Autodesk Navisworks that process DWFX files.
What is the potential impact of CVE-2024-12669?
The potential impact of CVE-2024-12669 includes system crashes, exposure of sensitive information, and unauthorized code execution.