CVE-2024-7671: DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7671?
CVE-2024-7671 is considered a critical severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-7671?
To mitigate CVE-2024-7671, users should update their Autodesk Navisworks software to the latest version provided by Autodesk.
What types of attacks can exploit CVE-2024-7671?
CVE-2024-7671 can be exploited to perform out-of-bounds write attacks, potentially leading to crashes or arbitrary code execution.
Which versions of Autodesk Navisworks are affected by CVE-2024-7671?
CVE-2024-7671 affects Autodesk Navisworks versions 2025, 2025.1, and 2025.2.
What is the impact of exploiting CVE-2024-7671?
Exploitation of CVE-2024-7671 can lead to application crashes, writing sensitive data, or executing arbitrary code within the process.