Tuesday, September 30th, 2008...12:21 pm...by: Anthony

Autodesk Design Review DWF Viewer Vulnerability

Jump to Comments

Secunia is reporting a vulnerability with Autodesk’s Design Review DWF Viewer which can lead to a compromised PC.

The vulnerability stems from a flaw in the ActiveX control including the insecure “SaveAs()” method. If exploited, arbitrary files on the compromised computer can be overwritten.

This vulnerability was originally discovered by “bruiser” from Nine Situations Group and outlined here.  Bruiser tested the vulnerability using Internet Explorer 6 along with Revit Architecture 2009 SP2 and Autodesk Design Review 2009.

DWF is a very popular file format for quickly and easily sending drawing files through email, among other things.  Many CAD users prefer DWF because of its vector based capabilities, small file size and the ability for people to view drawing files without having AutoCad installed.  I previously posted on the benefits of DWF for CAD users.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Google
  • Facebook
  • SphereIt
  • Reddit
  • Technorati
  • LinkedIn
  • Netvouz
  • description
  • ThisNext
  • MisterWong
  • Wists
  • BlogMemes
  • Furl
  • NewsVine
  • Slashdot
  • Spurl
  1. Autodesk Announces DWF Viewer 7 is Available Autodesk has announced the released of DWF Viewer 7.  This...
  2. Autodesk DWF Viewer 7.0 Issues Ok...so you have installed the new DWF Viewer 7.0 on...
  3. Autodesk Downloads Autocad 2006 Trial Version FREE This is a full version...
  4. DWG TrueView: DWF in Black & White We make liberal use of DWF when corresponding with our...
  5. New Autodesk Product Coming Soon It is codenamed "Vespa" (yeah...like the scooter :)). It allows...

Here are a Few Related Posts

2 Comments

Leave a Reply