AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2008-4472

HIGH · CVSS 9.3 EPSS 7.84% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-10-07 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2008-4472
Severity
HIGH
CVSS
9.3
EPSS
7.84%

Original Filing — NVD Description

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.