CVE-2025-10882
7.8Autodesk · Shared Components
A maliciously crafted X_T file can trigger an Out-of-Bounds Write vulnerability in Autodesk Shared Components, potentially allowing arbitrary code execution when parsed.
Executive summary
An Out-of-Bounds Write vulnerability in Autodesk Shared Components allows attackers to potentially execute arbitrary code or corrupt data through a specially crafted file.
Vulnerability
This is an Out-of-Bounds Write flaw (CWE-787) triggered when the application parses a malformed X_T file. The vulnerability requires user interaction, such as opening a malicious file, and operates in the context of the user process.
Business impact
Successful exploitation of this vulnerability could lead to a complete compromise of the affected user session, including unauthorized data access or system instability. With a CVSS score of 7.8, this is a High severity issue that poses a significant risk to workstations handling sensitive engineering data. Potential consequences include data corruption, service disruption, and the potential for remote code execution on the host machine.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or the latest available version provided in the official Autodesk security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior occurring immediately after opening external X_T files.
Compensating Controls: Ensure that users are instructed to only open X_T files from trusted sources, and utilize endpoint detection and response tools to monitor for suspicious child processes spawned by Autodesk software.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to design and engineering environments. Administrators should prioritize the deployment of the vendor-supplied security update across all affected workstations. Failure to patch leaves systems vulnerable to malicious file-based attacks that could bypass standard security controls.