CVE-2025-10886

7.8

Autodesk · Shared Components

A buffer overflow vulnerability in Autodesk Shared Components allows unauthenticated attackers to execute arbitrary code via a maliciously crafted MODEL file.

Executive summary

A critical memory corruption vulnerability in Autodesk Shared Components enables remote code execution if a user parses a specially crafted model file.

Vulnerability

This is a classic buffer overflow (CWE-120) triggered when the software parses a malformed MODEL file. The vulnerability allows an unauthenticated attacker to execute arbitrary code within the context of the current user process.

Business impact

Successful exploitation of this vulnerability could lead to a full compromise of the local system, including the theft of sensitive data or the installation of persistent malware. Given the CVSS score of 7.8, this represents a high risk to organizational security, particularly for engineering and design environments where Autodesk software is central to daily workflows.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.

Proactive Monitoring: Monitor system logs for unexpected application crashes or suspicious child processes being spawned by Autodesk design software.

Compensating Controls: Restrict the opening of files from untrusted or unknown sources and utilize endpoint protection software to detect and block malicious file execution attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The potential for arbitrary code execution necessitates immediate attention. Administrators should prioritize the deployment of the vendor patch across all workstations running affected Autodesk products to eliminate this attack vector.

More Autodesk CVEs

Sources