7.8
CVE-2024-11454
- EPSS 0.2%
- Veröffentlicht 09.12.2024 18:15:22
- Zuletzt bearbeitet 26.09.2025 17:48:10
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
Untrusted Search Path vulnerability in Autodesk Revit
A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.093 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| psirt@autodesk.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0025