HIGH · 9.3

CVE-2008-4472

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrar...

Vulnerability Description

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AutodeskDesign Review2009
AutodeskDwf ViewerAll versions
AutodeskRevit Architecture2009

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-4472?

CVE-2008-4472 is a vulnerability with a CVSS score of 9.3 (HIGH). The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrar...

How severe is CVE-2008-4472?

CVE-2008-4472 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-4472?

Check the references section above for vendor advisories and patch information. Affected products include: Autodesk Design Review, Autodesk Dwf Viewer, Autodesk Revit Architecture.