CVE-2025-10899

7.8

Autodesk · Shared Components

A maliciously crafted MODEL file in certain Autodesk products can trigger an Out-of-Bounds Write, potentially leading to arbitrary code execution.

Executive summary

An Out-of-Bounds Write vulnerability in Autodesk Shared Components exposes users to potential arbitrary code execution, data corruption, and system crashes through the parsing of malicious MODEL files.

Vulnerability

This vulnerability is an Out-of-Bounds Write (CWE-787) triggered when the software parses a malformed MODEL file. The attack requires user interaction, such as opening a malicious file, but does not require prior authentication.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational integrity and data confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as High severity. Exploitation could allow an attacker to gain control over the affected process, leading to unauthorized data access or disruption of critical engineering workflows.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later to remediate the vulnerability.

Proactive Monitoring: Review system logs for unusual application crashes or unexpected spikes in CPU usage associated with file parsing processes.

Compensating Controls: Implement strict file access policies and ensure that users only open model files from trusted, verified sources to reduce the risk of interaction with malicious content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Autodesk products must prioritize the deployment of the vendor-provided security updates. Given the potential for arbitrary code execution, patching the Shared Components library is essential to maintaining a secure environment and protecting sensitive project data from compromise.

More Autodesk CVEs

Sources