A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    26 Aug 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process. | 
29 Jan 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
 | 
07 Oct 2024, 18:34
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://autodesk.com/trust/security-advisories/adsk-sa-2024-0015 - Vendor Advisory | |
| First Time | Autodesk Autodesk navisworks | |
| CWE | CWE-787 | |
| CPE | cpe:2.3:a:autodesk:navisworks:2025.2:*:*:*:*:*:*:* cpe:2.3:a:autodesk:navisworks:2025.1:*:*:*:*:*:*:* cpe:2.3:a:autodesk:navisworks:2025:*:*:*:*:*:*:* | 
04 Oct 2024, 13:51
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
30 Sep 2024, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-09-30 21:15
Updated : 2025-08-26 19:15
NVD link : CVE-2024-7674
Mitre link : CVE-2024-7674
CVE.ORG link : CVE-2024-7674
JSON object : View
Products Affected
                autodesk
- navisworks
