CVE-2025-10881
7.8Autodesk · Shared Components
A heap-based buffer overflow in Autodesk Shared Components allows for potential arbitrary code execution via a maliciously crafted CATPRODUCT file.
Executive summary
Autodesk Shared Components contains a critical heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on an affected system.
Vulnerability
This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the software parses a malformed CATPRODUCT file. The attack requires user interaction, such as opening a malicious file, and can be performed by an unauthenticated attacker.
Business impact
The vulnerability carries a CVSS score of 7.8, representing a High severity risk. Successful exploitation could lead to full system compromise through arbitrary code execution, potentially resulting in the loss of proprietary design data, unauthorized access to internal networks, and significant operational disruption.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous process behavior associated with Autodesk software suites.
Compensating Controls: Implement file integrity monitoring and restrict the opening of untrusted or externally sourced CAD files within the environment.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, organizations using Autodesk products should prioritize patching the affected Shared Components. Administrators must ensure that all relevant Autodesk applications are updated to the secure version immediately to eliminate the risk of file-based exploitation.