CVE-2025-1658

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*

History

08 May 2025, 15:39

Type Values Removed Values Added
First Time Autodesk navisworks
Autodesk
Summary
  • (es) Un archivo DWFX complemento con fines maliciosos, al analizarse mediante Autodesk Navisworks, puede forzar una vulnerabilidad de lectura fuera de los límites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar código arbitrario en el contexto del proceso actual.
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0002 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0002 - Vendor Advisory
CPE cpe:2.3:a:autodesk:navisworks:*:*:*:*:*:*:*:*

01 Apr 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 13:15

Updated : 2025-05-08 15:39


NVD link : CVE-2025-1658

Mitre link : CVE-2025-1658

CVE.ORG link : CVE-2025-1658


JSON object : View

Products Affected

autodesk

  • navisworks
CWE
CWE-125

Out-of-bounds Read