VYPR
Unrated severityNVD Advisory· Published Sep 30, 2024· Updated Aug 26, 2025

DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software

CVE-2024-7671

Description

A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Affected products

3
  • Autodesk/Navisworkscpe-rescue3 versions
    cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:*:*:*range: 2025
    • cpe:2.3:a:autodesk:navisworks_manage:2025:*:*:*:*:*:*:*range: 2025
    • cpe:2.3:a:autodesk:navisworks_simulate:2025:*:*:*:*:*:*:*range: 2025

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.