ZDI-24-1707: Autodesk Navisworks Freedom DWFX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Navisworks Freedom. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12179.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1707?
ZDI-24-1707 is a high severity vulnerability allowing remote code execution.
How do I fix ZDI-24-1707?
To fix ZDI-24-1707, apply the latest security updates provided by Autodesk for Navisworks Freedom.
Who is affected by ZDI-24-1707?
Only installations of Autodesk Navisworks Freedom are affected by ZDI-24-1707.
What is the attack vector for ZDI-24-1707?
The attack vector for ZDI-24-1707 requires user interaction, such as visiting a malicious page or opening a malicious file.
What type of vulnerability is ZDI-24-1707?
ZDI-24-1707 is a remote code execution vulnerability.