A critical vulnerability in Axis Communications' plugin for Autodesk Revit has exposed Azure Storage Account credentials, creating significant security risks for customers and enabling supply chain attacks targeting the architecture and engineering industries.

The vulnerability stems from hardcoded credentials embedded in signed Dynamic Link Libraries (DLLs) distributed to clients via the plugin’s Microsoft Installer (MSI) package . The security issue was discovered in July 2024, when Trend Micro’s VirusTotal rules detected Azure Shared Access Signature (SAS) tokens inside a digitally signed DLL named “ AzureBlobRestAPI.dll ”.
The affected component was issued to AEC Advanced Engineering Computation Aktiebolag, an Autodesk partner specializing in AutoCAD and Revit consulting. This discovery initiated a remediation process that lasted months and included multiple vulnerability reports and patches.
See also: PoC Exploit for Lenovo code execution vulnerability
The exposed credentials provided unauthorized read and write access to three Azure storage accounts belonging to Axis Communications, a Swedish multinational company specializing in network video solutions and surveillance technology. These accounts contained critical assets, including MSI installers for the Axis Plugin for Autodesk Revit and Revit Family Architecture (RFA) files used by customers for building information modeling projects.
The impact of the vulnerability was amplified by the ability of attackers to replace legitimate files with malicious versions, essentially exploiting the trusted distribution mechanism.
Trend Micro analysts have identified issues beyond credential disclosure. Through their Zero Day Initiative (ZDI) research, they discovered multiple remote code execution in Autodesk Revit that could be triggered by importing malicious RFA files.

This combination of vulnerabilities created a dangerous attack vector where malicious actors could potentially compromise storage accounts, upload crafted RFA files, and achieve a mass breach of Axis Communications customers using Autodesk Revit software. The discovery highlights broader supply chain security risks within the architecture and engineering software ecosystem.
See also: Happy DOM Vulnerability: 2.7 Million Users at Risk
The plugin's design flaws show how trusted third-party integrations can become attack vectors when proper security controls are not implemented.
Axis Communications: Technical analysis of the attack
The technical basis of the vulnerability lies in poor credential management practices within the plugin architecture. The researchers found clear-text Azure SAS tokens and key pairs shared access for two Azure storage accounts named “axisfiles” and “axiscontentfiles” (encased inside a private method called “internalSetEnvironment” of the “AzureBlobRestAPI.DataTypes.Classes.Global” class). The credentials provided extensive privileges, including full read, write, delete, list, append, create, update, modify, and execute permissions on the accounts.

This level of access allows attackers to not only access existing content but also modify distribution mechanisms and upload malicious files. When Axis Communications initially attempted to fix the issue with version 25.3.710, it implemented code obfuscation using tools such as Eazfuscator. However, this approach proved to be inadequate as obfuscated credentials could be easily decrypted using publicly available tools such as de4dot. Obfuscation merely provided security through obscurity, rather than addressing the fundamental design flaw of embedding credentials in client-side code.
See also: Oracle E-Business Suite: New RCE vulnerability exposes data
Even after implementing read-only SAS tokens in version 25.3.711, the issue remained unresolved. Finally, Axis Communications confirmed that this vulnerability and others have been fully patched in the current version 25.3.718.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The company has also taken precautionary measures to notify affected partners and customers, emphasizing that the Autodesk Revit add-in is only provided to select partners and is generally not accessible for public use.
