CVE-2025-14593
7.8Autodesk · Shared Components
A crafted CATPART file can cause an Out-of-Bounds Read in Autodesk Shared Components, potentially leading to a crash, information disclosure, or arbitrary code execution.
Executive summary
Autodesk Shared Components contains an out-of-bounds read vulnerability that allows a local attacker to execute arbitrary code or access sensitive information via a malicious CATPART file.
Vulnerability
This vulnerability is an out-of-bounds read occurring during the parsing of CATPART files. It requires user interaction to open the malicious file and can be triggered by an unauthenticated local user.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to execute code with the permissions of the user running the Autodesk software, leading to unauthorized access to sensitive design data or system compromise.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Review system logs for unexpected application crashes or anomalous process behavior when handling CAD file formats.
Compensating Controls: Implement strict file access controls and ensure that users do not open untrusted or unexpected CATPART files from external sources.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the high CVSS score and the potential for arbitrary code execution, this vulnerability poses a significant risk to engineering and design environments. Administrators must prioritize the deployment of the vendor-provided updates to all systems utilizing the affected Autodesk Shared Components to eliminate the attack vector.