VYPR
High severity7.8NVD Advisory· Published Sep 30, 2024· Updated Jun 17, 2026

CVE-2024-7670

CVE-2024-7670

Description

A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Affected products

7
  • Autodesk/Navisworksllm-fuzzy7 versions
    (expand)+ 6 more
    • (no CPE)
    • cpe:2.3:a:autodesk:navisworks:2025:*:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:navisworks:2025.1:*:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:navisworks:2025.2:*:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:*:*:*range: 2025
    • cpe:2.3:a:autodesk:navisworks_simulate:2025:*:*:*:*:*:*:*range: 2025
    • cpe:2.3:a:autodesk:navisworks_manage:2025:*:*:*:*:*:*:*range: 2025

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.