CVE-2008-4472

Autodesk Design Review and Revit Architecture 2009 - Remote Code Execution via LiveUpdate ActiveX ApplyPatch Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4472. PoCs published by Nine:Situations:Group.

AI-analyzed exploit summary This exploit leverages two vulnerabilities in Autodesk DWF Viewer: an insecure SaveAS() method to write arbitrary files and an ApplyPatch() method to execute them. It demonstrates remote code execution by saving a malicious HTA file and executing it via the LiveUpdate module.

Description

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nine:Situations:Group · htmlremotewindows
https://www.exploit-db.com/exploits/6630

This exploit leverages two vulnerabilities in Autodesk DWF Viewer: an insecure SaveAS() method to write arbitrary files and an ApplyPatch() method to execute them. It demonstrates remote code execution by saving a malicious HTA file and executing it via the LiveUpdate module.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Autodesk DWF Viewer Control (AdView.dll v9.0.0.96) and LiveUpdate Module (LiveUpdate16.DLL 17.2.56)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 6 · Autodesk DWF Viewer or Design Review 2009 must be installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45521
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31490
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6630
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4361
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2704
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/496847/100/0/threaded

Scores

EPSS 0.0784
EPSS Percentile 93.9%

Details

CWE
CWE-264
Status published
Products (3)
autodesk/design_review 2009
autodesk/dwf_viewer
autodesk/revit_architecture 2009 sp2
Published Oct 07, 2008
Tracked Since Feb 18, 2026