PT-2025-14101 · Autodesk · Autodesk Navisworks Freedom
Published
2025-04-01
·
Updated
2025-08-19
·
CVE-2025-1659
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk Navisworks Freedom 2025
Description
A maliciously crafted DWFX file can cause an Out-of-Bounds Read issue when parsed through the software. This can be leveraged by a malicious actor to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Recommendations
For Autodesk Navisworks Freedom 2025, avoid parsing untrusted DWFX files until a patch is available. As a temporary workaround, consider restricting the use of DWFX file parsing functionality to minimize the risk of exploitation.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Navisworks Freedom