Show filters
272 Total Results
Displaying 11-20 of 272
Sort by:
Attacker Value
Unknown

CVE-2024-12191

Disclosure Date: December 17, 2024 (last updated February 10, 2025)
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-12179

Disclosure Date: December 17, 2024 (last updated January 29, 2025)
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-12178

Disclosure Date: December 17, 2024 (last updated January 29, 2025)
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-11422

Disclosure Date: December 17, 2024 (last updated February 10, 2025)
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-11608

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-11454

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.
0
Attacker Value
Unknown

CVE-2024-11268

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.
0
Attacker Value
Unknown

CVE-2023-7298

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-9500

Disclosure Date: November 15, 2024 (last updated January 28, 2025)
A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.
0
Attacker Value
Unknown

CVE-2024-7995

Disclosure Date: November 05, 2024 (last updated January 28, 2025)
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.
0