CVE-2025-5038
7.8Autodesk · AutoCAD, Shared Components
A memory corruption vulnerability in Autodesk products allows arbitrary code execution via maliciously crafted X_T files.
Executive summary
A critical memory corruption vulnerability in Autodesk AutoCAD and Shared Components allows an attacker to execute arbitrary code through the processing of a specially crafted X_T file.
Vulnerability
This is a buffer overflow vulnerability (CWE-120) triggered when the software parses a malformed X_T file, allowing an attacker to achieve arbitrary code execution in the context of the current user process.
Business impact
Successful exploitation of this vulnerability can lead to full system compromise, as the attacker can execute arbitrary code with the privileges of the user running the Autodesk application. Given the CVSS score of 7.8, this represents a high-severity risk that could result in sensitive design data theft, unauthorized access to corporate networks, or disruption of engineering workflows.
Remediation
Immediate Action: Update Autodesk AutoCAD and Shared Components to the latest versions specified in the vendor security advisory (ADSK-SA-2025-0015).
Proactive Monitoring: Monitor workstation logs for unexpected process execution or crashes associated with Autodesk software while processing external files.
Compensating Controls: Implement strict file access controls and ensure that users only open X_T files from trusted sources to prevent the introduction of malicious content.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing Autodesk software should prioritize patching affected systems to eliminate the risk of memory corruption. Administrators must ensure that all instances of AutoCAD and associated Shared Components are updated to the versions identified in the vendor advisory to prevent potential code execution attacks.