CVE-2025-10889
7.8Autodesk · Shared Components
A memory corruption vulnerability in Autodesk Shared Components allows arbitrary code execution when parsing a maliciously crafted CATPART file.
Executive summary
A memory corruption vulnerability in Autodesk Shared Components, triggered by processing malicious CATPART files, poses a significant risk of arbitrary code execution to end-user systems.
Vulnerability
This vulnerability is a classic buffer overflow (CWE-120) that occurs when the software processes specially crafted CATPART files. An unauthenticated attacker can trigger this flaw by enticing a user to open a malicious file, leading to arbitrary code execution within the context of the current process.
Business impact
The potential for arbitrary code execution creates a high risk of total system compromise, data theft, and unauthorized access to sensitive engineering designs. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the significant impact on confidentiality, integrity, and availability despite the requirement for user interaction.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official vendor advisory (ADSK-SA-2025-0024).
Proactive Monitoring: Monitor endpoint processes for unexpected crashes or anomalous behavior associated with file parsing modules within Autodesk applications.
Compensating Controls: Implement strict file-handling policies and utilize endpoint detection and response (EDR) solutions to block or alert on the execution of untrusted or externally sourced CAD files.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a severe threat to design environments and intellectual property. IT administrators must prioritize the deployment of the vendor-provided security updates across all workstations utilizing the affected Autodesk Shared Components to prevent potential exploitation.