CVE-2025-5043
7.8Autodesk · AutoCAD, Shared Components
A heap-based buffer overflow in Autodesk products allows attackers to execute arbitrary code or access sensitive data via a maliciously crafted 3DM file.
Executive summary
A heap-based buffer overflow vulnerability in Autodesk AutoCAD and Shared Components poses a significant risk of remote code execution and data compromise.
Vulnerability
This is a heap-based buffer overflow (CWE-122) triggered when the software parses a specially crafted 3DM file. The vulnerability can be exploited by an unauthenticated attacker, provided the user is tricked into importing or linking a malicious file.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code within the context of the user process, potentially leading to unauthorized data access, system crashes, or full system compromise. With a CVSS score of 7.8, this flaw represents a high risk to organizational security, particularly for engineering and design environments where sensitive intellectual property is handled.
Remediation
Immediate Action: Apply the security updates provided by Autodesk in their official advisory (ADSK-SA-2025-0015) to patch the affected AutoCAD and Shared Components versions.
Proactive Monitoring: Monitor system logs for unexpected application crashes or unauthorized attempts to access or import 3DM files from untrusted sources.
Compensating Controls: Implement strict file-handling policies that restrict the import of 3DM files from unknown or unverified external parties until the software has been patched.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The high CVSS score highlights the severity of this heap-based overflow, which could facilitate remote code execution if a user is successfully lured into opening a malicious file. IT administrators should prioritize the deployment of the vendor-supplied patches across all affected workstations and design servers immediately to eliminate this attack vector.