Description


A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

Related CPE's


a

autodesk

navisworks

3

Weaknesses



CWE-416


CWE-416

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2024-09-30T19:15:04.613Z

1 year ago

Last modified

2025-01-29T16:15:29.437Z

1 year ago