Autodesk Design Review Insecure Library Loading Vulnerability
The vulnerability is caused due to the application loading libraries (e.g. dwmapi.dll, whiptk_wt.7.12.601.dll, xaml_wt.7.6.0.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a DWF file located on a remote WebDAV or SMB share.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 2011 22.214.171.124 and also reported in version 2010. Other versions may also be affected.