CVE-2025-10882

7.8

Autodesk · Shared Components

A maliciously crafted X_T file can trigger an Out-of-Bounds Write vulnerability in Autodesk Shared Components, potentially allowing arbitrary code execution when parsed.

Executive summary

An Out-of-Bounds Write vulnerability in Autodesk Shared Components allows attackers to potentially execute arbitrary code or corrupt data through a specially crafted file.

Vulnerability

This is an Out-of-Bounds Write flaw (CWE-787) triggered when the application parses a malformed X_T file. The vulnerability requires user interaction, such as opening a malicious file, and operates in the context of the user process.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected user session, including unauthorized data access or system instability. With a CVSS score of 7.8, this is a High severity issue that poses a significant risk to workstations handling sensitive engineering data. Potential consequences include data corruption, service disruption, and the potential for remote code execution on the host machine.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or the latest available version provided in the official Autodesk security advisory.

Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior occurring immediately after opening external X_T files.

Compensating Controls: Ensure that users are instructed to only open X_T files from trusted sources, and utilize endpoint detection and response tools to monitor for suspicious child processes spawned by Autodesk software.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant risk to design and engineering environments. Administrators should prioritize the deployment of the vendor-supplied security update across all affected workstations. Failure to patch leaves systems vulnerable to malicious file-based attacks that could bypass standard security controls.

More Autodesk CVEs

Sources