Description


A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Related CPE's


a

autodesk

navisworks

3

Weaknesses



CWE-787


CWE-787

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2024-09-30T19:15:04.070Z

1 year ago

Last modified

2025-08-26T17:15:33.330Z

6 months ago