CVE-2025-10885

7.8

Autodesk · Installer

A vulnerability in the Autodesk Installer allows local, low-privileged users to achieve privilege escalation to NT AUTHORITY/SYSTEM via insufficient binary validation.

Executive summary

A high-severity privilege escalation vulnerability in the Autodesk Installer allows local attackers to execute arbitrary code with SYSTEM privileges.

Vulnerability

This vulnerability involves improper validation of loaded binaries, categorized under CWE-250 (Execution with Unnecessary Privileges). A local attacker with low-privilege access can exploit this flaw to execute code as the SYSTEM user on the host machine.

Business impact

The ability for a low-privileged user to escalate to SYSTEM access represents a total compromise of the affected host. This could lead to full data exfiltration, the installation of persistent malware, and complete loss of control over the compromised system. With a CVSS score of 7.8, this vulnerability poses a significant risk to organizational integrity and security posture.

Remediation

Immediate Action: Update the Autodesk Installer to version 2.19 or the latest available version provided by the vendor.

Proactive Monitoring: Monitor system logs for unauthorized binary execution or unexpected processes running under the NT AUTHORITY/SYSTEM context.

Compensating Controls: Restrict local user access to sensitive directories and enforce strict application allowlisting to prevent the execution of unauthorized or untrusted binaries.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for full system compromise, this vulnerability should be treated with high priority. Organizations using the Autodesk Installer must ensure that the software is updated to the version identified in the vendor advisory as soon as possible to prevent local privilege escalation attempts.

More Autodesk CVEs

Sources