Unrated severityNVD Advisory· Published Dec 17, 2024· Updated Aug 26, 2025
DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software
CVE-2024-12192
Description
A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected products
4cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:windows:*:*+ 3 more
- cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:windows:*:*range: 2025
- cpe:2.3:a:autodesk:navisworks_manage:2025:*:*:*:*:windows:*:*range: 2025
- cpe:2.3:a:autodesk:navisworks_simulate:2025:*:*:*:*:windows:*:*range: 2025
- (no CPE)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.