CVE-2025-6635
7.8Autodesk · Shared Components
A crafted PRT file imported into Autodesk products can trigger an Out-of-Bounds Read, potentially leading to application crashes, unauthorized data disclosure, or arbitrary code execution.
Executive summary
Autodesk Shared Components contain an Out-of-Bounds Read vulnerability that allows remote attackers to execute arbitrary code or access sensitive data through maliciously crafted PRT files.
Vulnerability
This is an Out-of-Bounds Read vulnerability (CWE-125) triggered when the software processes a specially crafted PRT file. The vulnerability requires user interaction to open or import the file, but it does not require prior authentication to exploit.
Business impact
The potential for arbitrary code execution poses a significant risk to organizational integrity, as it grants an attacker the ability to operate within the security context of the affected user. Successful exploitation may result in full system compromise, the exfiltration of sensitive design data, or unauthorized access to internal network resources. With a CVSS score of 7.8, this vulnerability is classified as High severity due to its potential to cause total system impact.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.7.0.10 or later as specified in the official Autodesk security advisory ADSK-SA-2025-0015.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous process behavior following the import of third party PRT files.
Compensating Controls: Implement strict file validation policies and restrict the import of untrusted PRT files from external or unverified sources until patches are fully deployed.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of this vulnerability and the potential for arbitrary code execution, it is imperative that all affected Autodesk installations are updated to the patched version immediately. Security teams should prioritize this update across all workstations and servers that utilize the vulnerable shared components to mitigate the risk of data loss or system takeover.