CVE-2024-11454

HIGH

Autodesk Revit - Code Injection

Title source: llm
STIX 2.1

Description

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.

Scores

CVSS v3 7.8
EPSS 0.0041
EPSS Percentile 61.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (1)
autodesk/revit 2025 - 2025.4
Published Dec 09, 2024
Tracked Since Feb 18, 2026