CVE-2025-10900
7.8Autodesk · Shared Components
A maliciously crafted MODEL file can trigger an Out-of-Bounds Write vulnerability in Autodesk Shared Components, potentially allowing arbitrary code execution.
Executive summary
Autodesk Shared Components are vulnerable to an Out-of-Bounds Write flaw that may lead to arbitrary code execution when processing specially crafted MODEL files.
Vulnerability
This vulnerability involves a CWE-787 Out-of-Bounds Write flaw triggered by parsing malicious MODEL files, which may be exploited by an attacker to cause system crashes, data corruption, or arbitrary code execution in the context of the current process. The attack requires user interaction to open the malicious file, though it does not require prior authentication.
Business impact
The potential for arbitrary code execution poses a significant threat to data confidentiality, integrity, and system availability. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to compromise local workstations or servers, leading to unauthorized access to sensitive design data or intellectual property.
Remediation
Immediate Action: Users should immediately review the Autodesk security advisory ADSK-SA-2025-0024 and apply the necessary updates to the affected Shared Components to remediate this vulnerability.
Proactive Monitoring: Security teams should monitor system logs for unusual crashes or abnormal process behavior associated with Autodesk applications during file parsing operations.
Compensating Controls: Implement file integrity monitoring and restrict the opening of untrusted or externally sourced MODEL files within the environment until the software is patched.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the risk of arbitrary code execution, organizations should prioritize updating all instances of Autodesk Shared Components. Users are strongly urged to verify their current version numbers against the affected range and apply the vendor provided patches as soon as they are available to prevent potential exploitation.