CVE-2025-5039

7.8

Autodesk · AutoCAD, AutoCAD LT, RealDWG, 3ds Max

Autodesk applications are vulnerable to arbitrary code execution via an untrusted search path flaw when loading maliciously crafted binary files.

Executive summary

Autodesk applications are vulnerable to remote code execution due to an untrusted search path flaw, posing a significant risk to system integrity.

Vulnerability

This vulnerability is caused by an untrusted search path (CWE-426), which allows a local attacker to execute arbitrary code in the context of the current process if a maliciously crafted binary file is placed in a location where the software attempts to load it. The attack requires user interaction to load the file, but does not require authentication.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the same privileges as the user running the affected Autodesk software. Given the CVSS score of 7.8, this constitutes a high risk, as it could lead to full system compromise, data theft, or the installation of persistent backdoors on engineering workstations.

Remediation

Immediate Action: Update all affected Autodesk products to the versions specified in the Autodesk security advisory ADSK-SA-2025-0014.

Proactive Monitoring: Monitor endpoint logs for suspicious file system activity, particularly the creation or execution of binary files in unexpected directories by Autodesk processes.

Compensating Controls: Ensure that users operate with the principle of least privilege to limit the impact of code execution and restrict write access to application directories.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The risk posed by this vulnerability is significant, particularly in environments where users frequently import external files. Administrators should prioritize the deployment of the provided patches to all workstations running the affected Autodesk software suites. Failure to patch may expose critical design infrastructure to unauthorized code execution and potential data breaches.

More Autodesk CVEs

Sources