CVE-2008-4472
Summary
| CVE | CVE-2008-4472 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-07 20:00:17 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Autodesk | Design Review | 2009 | All | All | All |
| Application | Autodesk | Dwf Viewer | All | All | All | All |
| Application | Autodesk | Revit Architecture | 2009 | sp2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Autodesk 'LiveUpdate16.DLL' ActiveX Control Arbitrary Program Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Autodesk DWF Viewer Control / LiveUpdate Module remote code execution exploit | af854a3a-2127-422b-91ae-364da2661108 | retrogod.altervista.org | |
| Autodesk | 3D Design, Engineering & Construction Software | af854a3a-2127-422b-91ae-364da2661108 | usa.autodesk.com | |
| Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution - Windows remote Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Live Update Hotfix | af854a3a-2127-422b-91ae-364da2661108 | images.autodesk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.