CVE-2024-7670: DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7670?
CVE-2024-7670 is categorized with a high severity due to its potential for causing crashes and executing arbitrary code.
How do I fix CVE-2024-7670?
To fix CVE-2024-7670, users should update Autodesk Navisworks to the latest version as recommended by security advisories.
What does CVE-2024-7670 affect?
CVE-2024-7670 affects specific versions of Autodesk Navisworks, including 2025, 2025.1, and 2025.2.
What can an attacker do with CVE-2024-7670?
An attacker can exploit CVE-2024-7670 to cause a crash, read sensitive data, or execute arbitrary code in the context of the running process.
Which file type is involved in CVE-2024-7670?
CVE-2024-7670 involves a maliciously crafted DWFX file that can trigger the vulnerability when parsed.