CVE-2025-5042

7.8

Autodesk · Revit and Revit LT

A maliciously crafted RFA file parsed in Autodesk Revit or Revit LT can trigger an out-of-bounds read, potentially leading to arbitrary code execution, sensitive data disclosure, or system crashes.

Executive summary

Autodesk Revit and Revit LT are vulnerable to an out-of-bounds read flaw that could allow a local attacker to execute arbitrary code or crash the application.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) triggered when the software parses a malformed RFA file. The vulnerability requires user interaction, such as opening a malicious file, and can be exploited by an unauthenticated user on the local system.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational integrity. Successful exploitation could allow an attacker to gain control over the user session, potentially leading to unauthorized access to sensitive project data or lateral movement within the workstation environment. With a CVSS score of 7.8, this vulnerability is considered High, as it provides a path for an attacker to compromise local system assets.

Remediation

Immediate Action: Update all instances of Autodesk Revit and Revit LT to the versions listed in the Autodesk security advisory (ADSK-SA-2025-0013) to patch this vulnerability.

Proactive Monitoring: Monitor workstation logs for unexpected application crashes or anomalous process behavior following the opening of RFA files from untrusted sources.

Compensating Controls: Implement strict file-handling policies that restrict the opening of RFA files received from external or unverified third parties until the software is patched.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a substantial risk to design and engineering workstations. Organizations should prioritize the deployment of the vendor-supplied updates across all affected Revit installations to ensure complete remediation. Failure to patch may expose sensitive design intellectual property to compromise through malicious RFA file manipulation.

More Autodesk CVEs

Sources