CVE-2025-5039
7.8Autodesk · AutoCAD, AutoCAD LT, RealDWG, 3ds Max
Autodesk applications are vulnerable to arbitrary code execution via an untrusted search path flaw when loading maliciously crafted binary files.
Executive summary
Autodesk applications are vulnerable to remote code execution due to an untrusted search path flaw, posing a significant risk to system integrity.
Vulnerability
This vulnerability is caused by an untrusted search path (CWE-426), which allows a local attacker to execute arbitrary code in the context of the current process if a maliciously crafted binary file is placed in a location where the software attempts to load it. The attack requires user interaction to load the file, but does not require authentication.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the same privileges as the user running the affected Autodesk software. Given the CVSS score of 7.8, this constitutes a high risk, as it could lead to full system compromise, data theft, or the installation of persistent backdoors on engineering workstations.
Remediation
Immediate Action: Update all affected Autodesk products to the versions specified in the Autodesk security advisory ADSK-SA-2025-0014.
Proactive Monitoring: Monitor endpoint logs for suspicious file system activity, particularly the creation or execution of binary files in unexpected directories by Autodesk processes.
Compensating Controls: Ensure that users operate with the principle of least privilege to limit the impact of code execution and restrict write access to application directories.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The risk posed by this vulnerability is significant, particularly in environments where users frequently import external files. Administrators should prioritize the deployment of the provided patches to all workstations running the affected Autodesk software suites. Failure to patch may expose critical design infrastructure to unauthorized code execution and potential data breaches.