CVE-2025-10888
7.8Autodesk · Shared Components
A maliciously crafted MODEL file can trigger an Out-of-Bounds Write vulnerability in Autodesk Shared Components, potentially leading to arbitrary code execution.
Executive summary
Autodesk Shared Components contains an Out-of-Bounds Write vulnerability that allows an attacker to execute arbitrary code or corrupt data through a specially crafted MODEL file.
Vulnerability
The vulnerability is an Out-of-Bounds Write (CWE-787) triggered when parsing malicious MODEL files. This flaw requires user interaction to open the file but does not require authentication to trigger.
Business impact
The ability to execute arbitrary code in the context of the current process poses a severe risk to organizational assets. With a CVSS score of 7.8, this vulnerability could lead to unauthorized system access, data theft, or complete compromise of the workstation running the affected Autodesk software.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or unauthorized process execution associated with Autodesk software suites.
Compensating Controls: Implement file integrity monitoring and restrict the ability of users to open untrusted or externally sourced MODEL files until the patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution and the high severity of the vulnerability, organizations should prioritize patching all systems utilizing the affected Autodesk Shared Components. Administrators must ensure that the update is deployed across all installations to prevent potential exploitation.