Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2024-11608

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-11454

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.
0
Attacker Value
Unknown

CVE-2024-11268

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.
0
Attacker Value
Unknown

CVE-2024-7994

Disclosure Date: October 16, 2024 (last updated January 28, 2025)
A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Attacker Value
Unknown

CVE-2024-7993

Disclosure Date: October 16, 2024 (last updated February 10, 2025)
A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Attacker Value
Unknown

CVE-2024-37008

Disclosure Date: August 21, 2024 (last updated August 26, 2024)
A maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Attacker Value
Unknown

CVE-2023-25002

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Attacker Value
Unknown

CVE-2023-29068

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Attacker Value
Unknown

CVE-2023-25004

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
Attacker Value
Unknown

CVE-2023-25003

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.