CVE-2025-6636
7.8Autodesk · Shared Components
A Use-After-Free vulnerability in Autodesk Shared Components allows attackers to cause crashes, disclose sensitive information, or execute arbitrary code via a maliciously crafted PRT file.
Executive summary
A critical Use-After-Free vulnerability in Autodesk Shared Components poses a significant risk of arbitrary code execution to users opening malicious PRT files.
Vulnerability
This is a Use-After-Free vulnerability (CWE-416) triggered during the parsing of PRT files. The vulnerability requires user interaction to open the malicious file, but does not require authentication to trigger.
Business impact
The exploitation of this vulnerability could lead to a full compromise of the affected workstation, including the unauthorized disclosure of sensitive data or the execution of arbitrary code within the current user context. With a CVSS score of 7.8, this flaw represents a high risk to organizational security, particularly for design and engineering teams handling proprietary intellectual property.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.7.0.10 or higher as specified in the vendor security advisory.
Proactive Monitoring: Review system and application logs for unusual crashes or unauthorized process execution patterns originating from Autodesk software.
Compensating Controls: Implement strict file access policies and ensure that users do not open PRT files from untrusted or unknown sources to limit the exposure vector.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be prioritized for remediation across all environments utilizing affected Autodesk products. Security teams should verify current software versions and apply the necessary patches immediately to mitigate the risk of exploitation.