VYPR
High severity7.8NVD Advisory· Published Apr 1, 2025· Updated Jun 17, 2026

CVE-2025-1660

CVE-2025-1660

Description

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Affected products

5
  • Autodesk/Navisworkscpe-rescue5 versions
    cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:windows:*:*+ 4 more
    • cpe:2.3:a:autodesk:navisworks_freedom:2025:*:*:*:*:windows:*:*range: 2025
    • cpe:2.3:a:autodesk:navisworks_simulate:2025:*:*:*:*:windows:*:*range: 2025
    • cpe:2.3:a:autodesk:navisworks_manage:2025:*:*:*:*:windows:*:*range: 2025
    • (no CPE)
    • cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*range: >=2025,<2025.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.