CVE-2025-6631

7.8

Autodesk · Shared Components

A maliciously crafted PRT file parsed by certain Autodesk products can trigger an Out-of-Bounds Write vulnerability, potentially leading to arbitrary code execution or system crashes.

Executive summary

An Out-of-Bounds Write vulnerability in Autodesk Shared Components exposes users to potential arbitrary code execution when processing specially crafted PRT files.

Vulnerability

This flaw is an Out-of-Bounds Write (CWE-787) triggered when the software parses a malformed PRT file. The attack requires user interaction, such as opening a malicious file, but does not require authentication to execute.

Business impact

Successful exploitation allows a malicious actor to execute arbitrary code within the context of the user process, cause application crashes, or corrupt critical data. With a CVSS score of 7.8, this vulnerability represents a high risk to organizational integrity and system availability, particularly in engineering environments where Autodesk products are heavily integrated into core workflows.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.7.0.10 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for unexpected application terminations or unauthorized file access attempts originating from the parsing process of PRT files.

Compensating Controls: Implement strict file-handling policies and utilize endpoint security solutions to scan files for malicious content before they are opened by authorized users.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The high severity of this vulnerability, combined with the potential for arbitrary code execution, necessitates immediate attention. Organizations should prioritize updating all instances of Autodesk Shared Components to the patched version to effectively neutralize the risk of exploitation.

More Autodesk CVEs

Sources