CVE-2025-10881

7.8

Autodesk · Shared Components

A heap-based buffer overflow in Autodesk Shared Components allows for potential arbitrary code execution via a maliciously crafted CATPRODUCT file.

Executive summary

Autodesk Shared Components contains a critical heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on an affected system.

Vulnerability

This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the software parses a malformed CATPRODUCT file. The attack requires user interaction, such as opening a malicious file, and can be performed by an unauthenticated attacker.

Business impact

The vulnerability carries a CVSS score of 7.8, representing a High severity risk. Successful exploitation could lead to full system compromise through arbitrary code execution, potentially resulting in the loss of proprietary design data, unauthorized access to internal networks, and significant operational disruption.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.

Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous process behavior associated with Autodesk software suites.

Compensating Controls: Implement file integrity monitoring and restrict the opening of untrusted or externally sourced CAD files within the environment.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, organizations using Autodesk products should prioritize patching the affected Shared Components. Administrators must ensure that all relevant Autodesk applications are updated to the secure version immediately to eliminate the risk of file-based exploitation.

More Autodesk CVEs

Sources