CVE-2025-10889

7.8

Autodesk · Shared Components

A memory corruption vulnerability in Autodesk Shared Components allows arbitrary code execution when parsing a maliciously crafted CATPART file.

Executive summary

A memory corruption vulnerability in Autodesk Shared Components, triggered by processing malicious CATPART files, poses a significant risk of arbitrary code execution to end-user systems.

Vulnerability

This vulnerability is a classic buffer overflow (CWE-120) that occurs when the software processes specially crafted CATPART files. An unauthenticated attacker can trigger this flaw by enticing a user to open a malicious file, leading to arbitrary code execution within the context of the current process.

Business impact

The potential for arbitrary code execution creates a high risk of total system compromise, data theft, and unauthorized access to sensitive engineering designs. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the significant impact on confidentiality, integrity, and availability despite the requirement for user interaction.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official vendor advisory (ADSK-SA-2025-0024).

Proactive Monitoring: Monitor endpoint processes for unexpected crashes or anomalous behavior associated with file parsing modules within Autodesk applications.

Compensating Controls: Implement strict file-handling policies and utilize endpoint detection and response (EDR) solutions to block or alert on the execution of untrusted or externally sourced CAD files.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a severe threat to design environments and intellectual property. IT administrators must prioritize the deployment of the vendor-provided security updates across all workstations utilizing the affected Autodesk Shared Components to prevent potential exploitation.

More Autodesk CVEs

Sources