Search

Find a vulnerability

Search criteria

    25 vulnerabilities found for revit by autodesk

    CVE-2026-7406 (GCVE-0-2026-7406)

    Vulnerability from cvelistv5 – Published: 2026-08-06 16:31 – Updated: 2026-09-18 14:24
    VLAI
    Title
    BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
    Summary
    A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 15:32 UTC
    CWE
    • CWE-822 - Untrusted Pointer Dereference
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.5.0 (semver)
    Affected: 2025.0.0 , < 2025.5.0 (semver)
    Affected: 2024.0.0 , < 2024.3.5 (semver)
        cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
        cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
        cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk DWG TrueView Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
        cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-7406",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T15:32:33.647250Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T15:35:08.763Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.5.0",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.5.0",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.3.5",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "DWG TrueView",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."
                }
              ],
              "value": "A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-153 Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-822",
                  "description": "CWE-822 Untrusted Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T14:24:44.819Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0012"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2026-7406",
        "datePublished": "2026-08-06T16:31:12.298Z",
        "dateReserved": "2026-04-29T13:03:51.562Z",
        "dateUpdated": "2026-09-18T14:24:44.819Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-7405 (GCVE-0-2026-7405)

    Vulnerability from cvelistv5 – Published: 2026-08-06 16:17 – Updated: 2026-09-18 14:24
    VLAI
    Title
    TIF File Parsing Out-of-Bounds Read in certain Autodesk products
    Summary
    A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 17:22 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.5.0 (semver)
    Affected: 2025.0.0 , < 2025.5.0 (semver)
    Affected: 2024.0.0 , < 2024.3.5 (semver)
        cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
        cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
        cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk DWG TrueView Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
        cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-7405",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T17:22:24.248444Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T17:22:51.825Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.5.0",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.5.0",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.3.5",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "DWG TrueView",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service"
                }
              ],
              "value": "A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-Bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T14:24:20.901Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0012"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TIF File Parsing Out-of-Bounds Read in certain Autodesk products",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2026-7405",
        "datePublished": "2026-08-06T16:17:54.589Z",
        "dateReserved": "2026-04-29T13:03:48.953Z",
        "dateUpdated": "2026-09-18T14:24:20.901Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-11803 (GCVE-0-2026-11803)

    Vulnerability from cvelistv5 – Published: 2026-08-06 15:58 – Updated: 2026-09-17 13:52
    VLAI
    Title
    PDF File Parsing Out-of-Bounds Read Vulnerability in in Certain Autodesk Desktop Products
    Summary
    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2027.0.0 , < 2027.2.0 (semver)
    Affected: 2026.0.0 , < 2026.5.0 (semver)
        cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
    Affected: 2025.0.0 , < 2025.1.4 (semver)
    Affected: 2024.0.0 , < 2024.1.9 (semver)
        cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
    Affected: 2025.0.0 , < 2025.1.4 (semver)
    Affected: 2024.0.0 , < 2024.1.9 (semver)
        cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-11803",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-08T03:55:29.449Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.2.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.5.0",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.1.4",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.1.9",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.1.4",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.1.9",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-540",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-540 Overread Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-Bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T13:52:08.090Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0011"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Out-of-Bounds Read Vulnerability in in Certain Autodesk Desktop Products",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2026-11803",
        "datePublished": "2026-08-06T15:58:36.195Z",
        "dateReserved": "2026-06-09T15:00:58.771Z",
        "dateUpdated": "2026-09-17T13:52:08.090Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-8325 (GCVE-0-2026-8325)

    Vulnerability from cvelistv5 – Published: 2026-08-06 15:58 – Updated: 2026-09-17 13:50
    VLAI
    Title
    PDF File Parsing Out-of-Bounds Write Vulnerability in Certain Autodesk Desktop Products
    Summary
    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2027.0.0 , < 2027.2.0 (semver)
    Affected: 2026.0.0 , < 2026.5.0 (semver)
    Affected: 2025.0.0 , < 2025.4.6 (semver)
    Affected: 2024.0.0 , < 2024.3.6 (semver)
        cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-8325",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-08T03:55:30.658Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.2.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.5.0",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.4.6",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.3.6",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process."
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-Bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T13:50:34.232Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0011"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Out-of-Bounds Write Vulnerability in Certain Autodesk Desktop Products",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2026-8325",
        "datePublished": "2026-08-06T15:58:02.242Z",
        "dateReserved": "2026-05-11T14:02:24.198Z",
        "dateUpdated": "2026-09-17T13:50:34.232Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-1289 (GCVE-0-2026-1289)

    Vulnerability from cvelistv5 – Published: 2026-08-06 15:57 – Updated: 2026-09-17 13:49
    VLAI
    Title
    PDF File Parsing Vulnerabilities in Certain Autodesk Desktop Products
    Summary
    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 00:00 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2027.0.0 , < 2027.2.0 (semver)
    Affected: 2026.0.0 , < 2026.5.0 (semver)
        cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
    Affected: 2025.0.0 , < 2025.1.4 (semver)
    Affected: 2024.0.0 , < 2024.1.9 (semver)
        cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.1.2 (semver)
    Affected: 2025.0.0 , < 2025.1.4 (semver)
    Affected: 2024.0.0 , < 2024.1.9 (semver)
        cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-1289",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-08T03:55:31.741Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.2.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.5.0",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.1.4",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.1.9",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.1.2",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.1.4",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.1.9",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process."
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-153: Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416: Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T13:49:16.359Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0011"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Vulnerabilities in Certain Autodesk Desktop Products",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2026-1289",
        "datePublished": "2026-08-06T15:57:13.827Z",
        "dateReserved": "2026-01-21T14:43:33.946Z",
        "dateUpdated": "2026-09-17T13:49:16.359Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-1288 (GCVE-0-2026-1288)

    Vulnerability from cvelistv5 – Published: 2026-06-17 15:27 – Updated: 2026-06-17 17:30
    VLAI
    Title
    RFA File Parsing Vulnerability in Autodesk Revit
    Summary
    A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-17 17:30 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2027.0.0 , < 2027.1.0 (semver)
    Affected: 2026.0.0 , < 2026.4.1 (semver)
    Affected: 2025.0.0 , < 2025.4.5 (semver)
    Affected: 2024.0.0 , < 2024.3.5 (semver)
        cpe:2.3:a:autodesk:revit:2027.1:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2026.4.1:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025.4.5:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024.3.5:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-1288",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-17T17:30:34.311655Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-17T17:30:51.745Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2027.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2026.4.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025.4.5:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024.3.5:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2027.1.0",
                  "status": "affected",
                  "version": "2027.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2026.4.1",
                  "status": "affected",
                  "version": "2026.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2025.4.5",
                  "status": "affected",
                  "version": "2025.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "2024.3.5",
                  "status": "affected",
                  "version": "2024.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RFA file, when converted to FormIt via \u201cConvert RFA to FormIt\u201d in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition."
                }
              ],
              "value": "A maliciously crafted RFA file, when converted to FormIt via \u201cConvert RFA to FormIt\u201d in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-153: Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-17T15:27:54.195Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0007"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RFA File Parsing Vulnerability in Autodesk Revit",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2026-1288",
        "datePublished": "2026-06-17T15:27:54.195Z",
        "dateReserved": "2026-01-21T14:43:31.726Z",
        "dateUpdated": "2026-06-17T17:30:51.745Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8354 (GCVE-0-2025-8354)

    Vulnerability from cvelistv5 – Published: 2025-09-23 13:20 – Updated: 2026-02-26 17:48
    VLAI
    Title
    RFA File Parsing Type Confusion Vulnerability
    Summary
    A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-24 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.3 (custom)
    Affected: 2025 , < 2025.4.4 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Revit LT Affected: 2026 , < 2026.3 (custom)
    Affected: 2025 , < 2025.4.4 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
        cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8354",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-24T03:55:16.087083Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:48:17.430Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.3",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.4",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.3",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.4",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-255",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-255 Manipulate Data Structures"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-843",
                  "description": "CWE-843 Type Confusion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-02T15:20:37.992Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0021"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RFA File Parsing Type Confusion Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-8354",
        "datePublished": "2025-09-23T13:20:03.452Z",
        "dateReserved": "2025-07-30T13:45:53.877Z",
        "dateUpdated": "2026-02-26T17:48:17.430Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8894 (GCVE-0-2025-8894)

    Vulnerability from cvelistv5 – Published: 2025-09-16 14:19 – Updated: 2026-02-26 17:48
    VLAI
    Title
    PDF File Parsing Heap-Based Buffer Overflow Vulnerability
    Summary
    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-17 03:55 UTC
    CWE
    • CWE-122 - Heap-Based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.3 (custom)
    Affected: 2025 , < 2025.4.3 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Revit LT Affected: 2026 , < 2026.3 (custom)
    Affected: 2025 , < 2025.4.3 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
        cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8894",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-17T03:55:48.155258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:48:30.125Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.3",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.3",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-Based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-06T15:19:39.631Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0018"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Heap-Based Buffer Overflow Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-8894",
        "datePublished": "2025-09-16T14:19:30.719Z",
        "dateReserved": "2025-08-12T15:51:59.648Z",
        "dateUpdated": "2026-02-26T17:48:30.125Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8893 (GCVE-0-2025-8893)

    Vulnerability from cvelistv5 – Published: 2025-09-16 14:17 – Updated: 2026-02-26 17:48
    VLAI
    Title
    PDF File Parsing Out-of-Bounds Write Vulnerability
    Summary
    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-17 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.3 (custom)
    Affected: 2025 , < 2025.4.3 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Revit LT Affected: 2026 , < 2026.3 (custom)
    Affected: 2025 , < 2025.4.3 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
        cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8893",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-17T03:55:47.169115Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:48:30.651Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.3",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.3",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-Bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-06T15:19:18.552Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0018"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Out-of-Bounds Write Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-8893",
        "datePublished": "2025-09-16T14:17:05.441Z",
        "dateReserved": "2025-08-12T15:51:57.737Z",
        "dateUpdated": "2026-02-26T17:48:30.651Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-5042 (GCVE-0-2025-5042)

    Vulnerability from cvelistv5 – Published: 2025-07-22 16:02 – Updated: 2026-02-26 17:50
    VLAI
    Title
    RFA File Parsing Out-of-Bounds Read Vulnerability
    Summary
    A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-24 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.2 (custom)
    Affected: 2025 , < 2025.4.3 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Revit LT Affected: 2026 , < 2026.2 (custom)
    Affected: 2025 , < 2025.4.3 (custom)
    Affected: 2024 , < 2024.3.4 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-5042",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-24T03:55:23.416407Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:50:25.096Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.2",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.2",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.4",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-Bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-06T15:21:12.952Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0013"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RFA File Parsing Out-of-Bounds Read Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-5042",
        "datePublished": "2025-07-22T16:02:51.214Z",
        "dateReserved": "2025-05-21T13:01:02.071Z",
        "dateUpdated": "2026-02-26T17:50:25.096Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-5040 (GCVE-0-2025-5040)

    Vulnerability from cvelistv5 – Published: 2025-07-10 11:31 – Updated: 2026-02-26 17:50
    VLAI
    Title
    RTE File Parsing Heap-Based Overflow Vulnerability
    Summary
    A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-11 03:55 UTC
    CWE
    • CWE-122 - Heap-Based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.2 (custom)
    Affected: 2025 , < 2025.4.2 (custom)
    Affected: 2024 , < 2024.3.3 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-5040",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-11T03:55:30.154382Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:50:48.149Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.2",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.3",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-Based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-19T13:17:58.621Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0012"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RTE File Parsing Heap-Based Overflow Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-5040",
        "datePublished": "2025-07-10T11:31:19.454Z",
        "dateReserved": "2025-05-21T13:00:59.934Z",
        "dateUpdated": "2026-02-26T17:50:48.149Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-5037 (GCVE-0-2025-5037)

    Vulnerability from cvelistv5 – Published: 2025-07-10 11:30 – Updated: 2026-02-26 17:50
    VLAI
    Title
    RFA File Parsing Memory Corruption Vulnerability
    Summary
    A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-11 03:55 UTC
    CWE
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.2 (custom)
    Affected: 2025 , < 2025.4.2 (custom)
    Affected: 2024 , < 2024.3.3 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-5037",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-11T03:55:29.295364Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T17:50:48.514Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.2",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.3",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-120",
                  "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-19T13:15:53.519Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0012"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RFA File Parsing Memory Corruption Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-5037",
        "datePublished": "2025-07-10T11:30:47.004Z",
        "dateReserved": "2025-05-21T13:00:57.526Z",
        "dateUpdated": "2026-02-26T17:50:48.514Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-5036 (GCVE-0-2025-5036)

    Vulnerability from cvelistv5 – Published: 2025-06-02 16:55 – Updated: 2026-02-26 18:27
    VLAI
    Title
    RFA File Parsing Use-After-Free Vulnerability
    Summary
    A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-03 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2026 , < 2026.1 (custom)
    Affected: 2025 , < 2025.4.2 (custom)
    Affected: 2024 , < 2024.3.3 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-5036",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-03T03:55:25.516311Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:27:42.234Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2026.1",
                  "status": "affected",
                  "version": "2026",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2025.4.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.3",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416 Use-After-Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-19T13:15:04.359Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0009"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RFA File Parsing Use-After-Free Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-5036",
        "datePublished": "2025-06-02T16:55:54.002Z",
        "dateReserved": "2025-05-21T13:00:56.336Z",
        "dateUpdated": "2026-02-26T18:27:42.234Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1274 (GCVE-0-2025-1274)

    Vulnerability from cvelistv5 – Published: 2025-04-15 20:58 – Updated: 2026-02-26 18:28
    VLAI
    Title
    RCS File Parsing Out-of-Bounds Write Vulnerability
    Summary
    A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-18 03:55 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4.1 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1274",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-18T03:55:39.221063Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:15.897Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-Bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T18:34:11.551Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0007"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "RCS File Parsing Out-of-Bounds Write Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-1274",
        "datePublished": "2025-04-15T20:58:04.157Z",
        "dateReserved": "2025-02-13T15:16:29.531Z",
        "dateUpdated": "2026-02-26T18:28:15.897Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1277 (GCVE-0-2025-1277)

    Vulnerability from cvelistv5 – Published: 2025-04-15 20:57 – Updated: 2026-02-26 18:28
    VLAI
    Title
    PDF File Parsing Memory Corruption Vulnerability
    Summary
    A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-18 03:55 UTC
    CWE
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4.1 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1277",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-18T03:55:37.654473Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:16.389Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-120",
                  "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T18:46:17.984Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0003"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Memory Corruption Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-1277",
        "datePublished": "2025-04-15T20:57:04.021Z",
        "dateReserved": "2025-02-13T15:16:32.655Z",
        "dateUpdated": "2026-02-26T18:28:16.389Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1656 (GCVE-0-2025-1656)

    Vulnerability from cvelistv5 – Published: 2025-04-15 20:56 – Updated: 2026-02-26 18:28
    VLAI
    Title
    PDF File Parsing Heap-based Overflow Vulnerability
    Summary
    A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-18 03:55 UTC
    CWE
    • CWE-122 - Heap-Based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4.1 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1656",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-18T03:55:36.223028Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:16.727Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-Based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T18:45:41.097Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0003"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Heap-based Overflow Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-1656",
        "datePublished": "2025-04-15T20:56:30.567Z",
        "dateReserved": "2025-02-24T20:01:54.134Z",
        "dateUpdated": "2026-02-26T18:28:16.727Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1273 (GCVE-0-2025-1273)

    Vulnerability from cvelistv5 – Published: 2025-04-15 20:56 – Updated: 2026-02-26 18:28
    VLAI
    Title
    PDF File Parsing Heap-Based Overflow Vulnerability
    Summary
    A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-18 03:55 UTC
    CWE
    • CWE-122 - Heap-Based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4.1 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2025 , < 2025.1.3 (custom)
    Affected: 2024 , < 2024.1.8 (custom)
    Affected: 2023 , < 2023.1.8 (custom)
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1273",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-18T03:55:34.685588Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:17.193Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.8",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.8",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-Based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-25T18:45:07.442Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0003"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Heap-Based Overflow Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-1273",
        "datePublished": "2025-04-15T20:56:04.970Z",
        "dateReserved": "2025-02-13T15:16:28.058Z",
        "dateUpdated": "2026-02-26T18:28:17.193Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-2497 (GCVE-0-2025-2497)

    Vulnerability from cvelistv5 – Published: 2025-04-15 20:55 – Updated: 2026-02-26 18:28
    VLAI
    Title
    DWG File Parsing Stack-Based Buffer Vulnerability
    Summary
    A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-18 03:55 UTC
    CWE
    • CWE-122 - Heap-Based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4.1 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-2497",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-18T03:55:33.292299Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:17.497Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-Based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-19T13:14:29.322Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0005"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "DWG File Parsing Stack-Based Buffer Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-2497",
        "datePublished": "2025-04-15T20:55:34.931Z",
        "dateReserved": "2025-03-18T13:00:16.699Z",
        "dateUpdated": "2026-02-26T18:28:17.497Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1275 (GCVE-0-2025-1275)

    Vulnerability from cvelistv5 – Published: 2025-04-15 20:54 – Updated: 2026-02-26 18:28
    VLAI
    Title
    JPG File Parsing Heap-Based Overflow Vulnerability
    Summary
    A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-18 03:55 UTC
    CWE
    • CWE-122 - Heap-Based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4.1 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Architecture Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Electrical Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Mechanical Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MEP Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD Plant 3D Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Civil 3D Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Advance Steel Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD MAP 3D Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk AutoCAD LT Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk DWG TrueView Affected: 2025 , < 2025.1.2 (custom)
    Affected: 2024 , < 2024.1.7 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:dwg_trueview:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1275",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-18T03:55:31.920563Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T18:28:18.106Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_architecture:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_architecture:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Architecture",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_electrical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_electrical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Electrical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mechanical:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mechanical:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Mechanical",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_mep:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_mep:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MEP",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_plant_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_plant_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD Plant 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:civil_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:civil_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Civil 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:advance_steel:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:advance_steel:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Advance Steel",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_map_3d:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_map_3d:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD MAP 3D",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:autocad_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:autocad_lt:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "AutoCAD LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:dwg_trueview:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:dwg_trueview:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:dwg_trueview:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "DWG TrueView",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1.2",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.1.7",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-Based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-19T12:47:53.443Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/autodesk-access/overview"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.autodesk.com/products/dwg-trueview/overview"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0006"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "JPG File Parsing Heap-Based Overflow Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2025-1275",
        "datePublished": "2025-04-15T20:54:30.139Z",
        "dateReserved": "2025-02-13T15:16:30.397Z",
        "dateUpdated": "2026-02-26T18:28:18.106Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-11608 (GCVE-0-2024-11608)

    Vulnerability from cvelistv5 – Published: 2024-12-09 17:53 – Updated: 2025-08-28 14:38
    VLAI
    Summary
    A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 18:03 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4 (custom)
    Affected: 2024 , < 2024.3.2 (custom)
    Affected: 2023 , < 2023.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
    Create a notification for this product.
    autodesk revit Affected: 2025
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "revit",
                "vendor": "autodesk",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2025"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11608",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T18:03:53.476189Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T18:05:18.311Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.7",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-28T14:38:16.647Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0026"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2024-11608",
        "datePublished": "2024-12-09T17:53:18.804Z",
        "dateReserved": "2024-11-21T20:20:48.343Z",
        "dateUpdated": "2025-08-28T14:38:16.647Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11454 (GCVE-0-2024-11454)

    Vulnerability from cvelistv5 – Published: 2024-12-09 17:48 – Updated: 2025-08-28 14:35
    VLAI
    Title
    Untrusted Search Path vulnerability in Autodesk Revit
    Summary
    A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 18:05 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
    Create a notification for this product.
    autodesk revit Affected: 2025
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "revit",
                "vendor": "autodesk",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2025"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11454",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T18:05:41.484045Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T18:07:39.304Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-471",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-471 Search Order Hijacking"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-426",
                  "description": "CWE-426 Untrusted Search Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-28T14:35:08.803Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0025"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Untrusted Search Path vulnerability in Autodesk Revit",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2024-11454",
        "datePublished": "2024-12-09T17:48:30.983Z",
        "dateReserved": "2024-11-19T20:14:29.710Z",
        "dateUpdated": "2025-08-28T14:35:08.803Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11268 (GCVE-0-2024-11268)

    Vulnerability from cvelistv5 – Published: 2024-12-09 17:42 – Updated: 2025-08-26 16:51
    VLAI
    Title
    PDF File Parsing Vulnerability in Autodesk Revit
    Summary
    A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 18:07 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.4 (custom)
    Affected: 2024 , < 2024.3.1 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11268",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T18:07:50.635674Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T18:07:57.640Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.4",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3.1",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-26T16:51:06.761Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0024"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PDF File Parsing Vulnerability in Autodesk Revit",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2024-11268",
        "datePublished": "2024-12-09T17:42:15.362Z",
        "dateReserved": "2024-11-15T17:53:44.142Z",
        "dateUpdated": "2025-08-26T16:51:06.761Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-7994 (GCVE-0-2024-7994)

    Vulnerability from cvelistv5 – Published: 2024-10-16 21:47 – Updated: 2025-01-28 20:10
    VLAI
    Title
    Stack-Based Buffer Overflow Vulnerability in Autodesk Revit
    Summary
    A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-18 17:59 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.3 (custom)
    Affected: 2024 , < 2024.3 (custom)
    Affected: 2023 , < 2023.1.6 (custom)
    Affected: 2022 , < 2022.1.8 (custom)
    Create a notification for this product.
    autodesk revit Affected: 2024
    Affected: 2025
        cpe:2.3:a:autodesk:revit:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:autodesk:revit:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "revit",
                "vendor": "autodesk",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2024"
                  },
                  {
                    "status": "affected",
                    "version": "2025"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7994",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-18T17:59:24.381901Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-18T18:01:01.085Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpe": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2022:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.3",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.6",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2022.1.8",
                  "status": "affected",
                  "version": "2022",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-28T20:10:30.617Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "url": "https://autodesk.com/trust/security-advisories/adsk-sa-2024-0017"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Stack-Based Buffer Overflow Vulnerability in Autodesk Revit",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2024-7994",
        "datePublished": "2024-10-16T21:47:51.258Z",
        "dateReserved": "2024-08-19T21:37:10.490Z",
        "dateUpdated": "2025-01-28T20:10:30.617Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-7993 (GCVE-0-2024-7993)

    Vulnerability from cvelistv5 – Published: 2024-10-16 21:47 – Updated: 2025-08-26 18:25
    VLAI
    Title
    Out-of-Bounds Write Vulnerability in Autodesk Revit
    Summary
    A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 16:17 UTC
    CWE
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.3 (custom)
    Affected: 2024 , < 2024.2.2 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
    Create a notification for this product.
    autodesk revit Affected: 2024 , < 2024.2.2 (custom)
    Affected: 2025 , < 2025.3 (custom)
        cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "revit",
                "vendor": "autodesk",
                "versions": [
                  {
                    "lessThan": "2024.2.2",
                    "status": "affected",
                    "version": "2024",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2025.3",
                    "status": "affected",
                    "version": "2025",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7993",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T16:17:26.757982Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T16:19:18.837Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.3",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.2.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-26T18:25:22.824Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0018"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Out-of-Bounds Write Vulnerability in Autodesk Revit",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2024-7993",
        "datePublished": "2024-10-16T21:47:31.739Z",
        "dateReserved": "2024-08-19T21:37:09.626Z",
        "dateUpdated": "2025-08-26T18:25:22.824Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-37008 (GCVE-0-2024-37008)

    Vulnerability from cvelistv5 – Published: 2024-08-21 10:02 – Updated: 2025-08-26 18:07
    VLAI
    Title
    Stack-based Overflow Vulnerability in Revit Software
    Summary
    A maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-22 18:53 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    Autodesk Revit Affected: 2025 , < 2025.1 (custom)
    Affected: 2024 , < 2024.2.2 (custom)
    Affected: 2023 , < 2023.1.5 (custom)
    Affected: 2022 , < 2022.1.7 (custom)
        cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit:2022:*:*:*:*:*:*:*
    Create a notification for this product.
    Autodesk Revit LT Affected: 2025 , < 2025.1 (custom)
    Affected: 2024 , < 2024.2.2 (custom)
    Affected: 2023 , < 2023.1.5 (custom)
    Affected: 2022 , < 2022.1.7 (custom)
        cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2023:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:2022:*:*:*:*:*:*:*
    Create a notification for this product.
    autodesk revit_lt Affected: 2025 , < 2025.1 (custom)
    Affected: 2024 , ≤ 2024.2.1 (semver)
    Affected: 2023 , ≤ 2023.1.4 (semver)
    Affected: 2022 , ≤ 2022.1.6 (semver)
        cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
        cpe:2.3:a:autodesk:revit_lt:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*",
                  "cpe:2.3:a:autodesk:revit_lt:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "revit_lt",
                "vendor": "autodesk",
                "versions": [
                  {
                    "lessThan": "2025.1",
                    "status": "affected",
                    "version": "2025",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "2024.2.1",
                    "status": "affected",
                    "version": "2024",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "2023.1.4",
                    "status": "affected",
                    "version": "2023",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "2022.1.6",
                    "status": "affected",
                    "version": "2022",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-37008",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-22T18:53:46.614281Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-26T21:08:41.231Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit:2022:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.2.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.5",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2022.1.7",
                  "status": "affected",
                  "version": "2022",
                  "versionType": "custom"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:autodesk:revit_lt:2025:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2024:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2023:*:*:*:*:*:*:*",
                "cpe:2.3:a:autodesk:revit_lt:2022:*:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "product": "Revit LT",
              "vendor": "Autodesk",
              "versions": [
                {
                  "lessThan": "2025.1",
                  "status": "affected",
                  "version": "2025",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2024.2.2",
                  "status": "affected",
                  "version": "2024",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2023.1.5",
                  "status": "affected",
                  "version": "2023",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2022.1.7",
                  "status": "affected",
                  "version": "2022",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.\u003c/p\u003e"
                }
              ],
              "value": "A maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-26T18:07:00.526Z",
            "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
            "shortName": "autodesk"
          },
          "references": [
            {
              "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0013"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Stack-based Overflow Vulnerability in Revit Software",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "assignerShortName": "autodesk",
        "cveId": "CVE-2024-37008",
        "datePublished": "2024-08-21T10:02:21.128Z",
        "dateReserved": "2024-05-30T20:11:46.550Z",
        "dateUpdated": "2025-08-26T18:07:00.526Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }