We are a bunch of tech geeks, coders and designers. Read more ...


« Autodesk Design Review DWF Viewer Vulnerability

Secunia is reporting a vulnerability with Autodesk’s Design Review DWF Viewer which can lead to a compromised PC.

The vulnerability stems from a flaw in the ActiveX control including the insecure “SaveAs()” method. If exploited, arbitrary files on the compromised computer can be overwritten.

This vulnerability was originally discovered by “bruiser” from Nine Situations Group and outlined here.  Bruiser tested the vulnerability using Internet Explorer 6 along with Revit Architecture 2009 SP2 and Autodesk Design Review 2009.

DWF is a very popular file format for quickly and easily sending drawing files through email, among other things.  Many CAD users prefer DWF because of its vector based capabilities, small file size and the ability for people to view drawing files without having AutoCad installed.  I previously posted on the benefits of DWF for CAD users.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Google
  • Facebook
  • SphereIt
  • Reddit
  • Technorati
  • LinkedIn
  • description
  • BlogMemes
  • Furl
  • NewsVine
  • Slashdot
  • blinkbits
  • BlinkList
  • Live
  • Sphinn
  • StumbleUpon
  • Yahoo! Buzz
your ad here

2 commentsto “Autodesk Design Review DWF Viewer Vulnerability”

  • October 14, 2008
    Volker Joseph wrote

    The Autodesk Design Review team is aware of the problem and we are working towards a resolution.

    I will post an announcement on http://www.dwf.blogs.com once we have made a solution available to our customers.

    Thank you,

    Volker

  • October 14, 2008
    Anthony wrote

    Thanks, Joseph. We will keep our eyes open for that DWF Viewer announcement.