ZDI-25-199: Autodesk Navisworks Freedom DWFX File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Navisworks Freedom. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1660.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-199?
ZDI-25-199 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix ZDI-25-199?
To mitigate ZDI-25-199, users should ensure they are using the latest version of Autodesk Navisworks Freedom and apply any available security patches.
Who is affected by ZDI-25-199?
ZDI-25-199 affects installations of Autodesk Navisworks Freedom prior to the release of the security updates.
What is required to exploit ZDI-25-199?
Exploitation of ZDI-25-199 requires user interaction, such as visiting a malicious webpage or opening a malicious file.
What kind of attack does ZDI-25-199 enable?
ZDI-25-199 enables remote attackers to execute arbitrary code on the affected systems.