Insecure DLL loading in Dynamo BIM - CVE-2020-7079
Published: May 25, 2020
Dynamo BIM
Autodesk
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to improper signature validation mechanism when automatically loading official Autodesk feature packages delivered at install time. A remote attacker can trick a victim into writing a malicious DLL into the installation area and execute arbitrary code on victim's system.