CVE-2025-10883
7.8Autodesk · Shared Components
A vulnerability in Autodesk Shared Components allows for an out-of-bounds read when parsing CATPRODUCT files, potentially leading to crashes, data disclosure, or arbitrary code execution.
Executive summary
A critical out-of-bounds read vulnerability in Autodesk Shared Components, tracked as CVE-2025-10883, poses a risk of arbitrary code execution and sensitive data exposure.
Vulnerability
This vulnerability is an out-of-bounds read (CWE-125) triggered when the software parses a maliciously crafted CATPRODUCT file. The attack requires user interaction to open a malicious file, but it does not require authentication to execute.
Business impact
The exploitation of this flaw can result in total technical impact, including unauthorized access to sensitive data and the potential for remote code execution in the context of the affected process. With a CVSS score of 7.8, this high-severity vulnerability could lead to significant system compromise if an attacker successfully lures a user into processing a malicious file.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior related to the parsing of external file formats.
Compensating Controls: Ensure that users are trained to exercise caution when opening files from untrusted sources, as the attack vector requires user interaction to initiate the malicious parsing process.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, organizations utilizing Autodesk software should prioritize patching the Shared Components library. Administrators should verify the version of the installed component and apply the vendor-provided update immediately to eliminate the risk of exploitation.