Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-4472Design Review vulnerability

CWE-2644 documents4 sources
Severity
9.3CRITICALNVD
EPSS
11.3%
top 6.45%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 7
Latest updateMay 2

Description

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cp4g-vr65-6767: The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate162022-05-02
CVEList
CVE-2008-4472: The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate162008-10-07

💥Exploits & PoCs

1
Exploit-DB
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution2008-09-30
CVE-2008-4472 — Autodesk Design Review vulnerability | cvebase