CVE-2025-10887
7.8Autodesk · Shared Components
Autodesk Shared Components contains a memory corruption vulnerability triggered by parsing malformed MODEL files, which may lead to arbitrary code execution.
Executive summary
A critical memory corruption vulnerability in Autodesk Shared Components allows an unauthenticated attacker to achieve arbitrary code execution via a maliciously crafted MODEL file.
Vulnerability
This vulnerability is a classic buffer overflow (CWE-120) triggered when the software parses a specially crafted MODEL file. An unauthenticated attacker can exploit this flaw to execute arbitrary code within the context of the user running the affected application.
Business impact
Successful exploitation of this flaw poses a severe risk to organizational security, as it allows for unauthorized code execution on end-user workstations. With a CVSS score of 7.8, this vulnerability is classified as High severity, indicating the potential for significant compromise of local system integrity and confidentiality. Organizations relying on Autodesk software face potential data exfiltration or lateral movement if attackers gain a foothold via this vector.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous process behavior associated with Autodesk product suites.
Compensating Controls: Implement file integrity monitoring and restrict the execution of untrusted MODEL files from external or unverified sources to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to endpoint security. Administrators must prioritize the deployment of the vendor-provided patch across all affected environments to prevent potential exploitation. Failure to update may leave systems vulnerable to remote compromise initiated through standard file-sharing workflows.