CVE-2025-10884
7.8Autodesk · Shared Components
A maliciously crafted CATPART file can trigger an Out-of-Bounds Write vulnerability in various Autodesk products, potentially leading to arbitrary code execution.
Executive summary
An Out-of-Bounds Write vulnerability in Autodesk Shared Components poses a significant risk of arbitrary code execution, data corruption, or system crashes when processing malicious CATPART files.
Vulnerability
This vulnerability is a memory corruption issue classified as an Out-of-Bounds Write (CWE-787), which can be triggered when the software parses a specially crafted CATPART file. The attack vector requires user interaction and local access, as the malicious file must be opened by an unsuspecting user within the affected product environment.
Business impact
The potential for arbitrary code execution in the context of the current process represents a critical threat to organizational security. Successful exploitation could lead to full system compromise, the exfiltration of sensitive design data, or significant operational downtime due to application crashes. Given the CVSS score of 7.8, this flaw is categorized as High severity, necessitating prompt attention to prevent unauthorized access or loss of intellectual property.
Remediation
Immediate Action: Organizations should update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Security teams should monitor system logs for unusual application crashes or unexpected file access patterns associated with Autodesk software.
Compensating Controls: Implement file integrity monitoring and restrict the opening of untrusted or externally sourced CATPART files to prevent the introduction of malicious content into the environment.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The risk posed by this memory corruption vulnerability is significant, particularly in engineering environments where external files are frequently processed. Administrators must prioritize the deployment of the vendor-provided updates to Autodesk Shared Components. Until patching is complete, users should exercise extreme caution when handling CATPART files from unverified or untrusted sources to mitigate the risk of triggering the exploit.