CVE-2024-11454

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
09/12/2024
Last modified:
26/09/2025

Description

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* 2025 (including) 2025.4 (excluding)


References to Advisories, Solutions, and Tools