CVE-2025-7497
7.8Autodesk · Shared Components
A maliciously crafted PRT file parsed by Autodesk products can lead to an Out-of-Bounds Write, potentially allowing for arbitrary code execution or system crashes.
Executive summary
A critical Out-of-Bounds Write vulnerability in Autodesk Shared Components allows attackers to achieve arbitrary code execution via a specially crafted PRT file.
Vulnerability
This vulnerability is an Out-of-Bounds Write (CWE-787) flaw that occurs when the software improperly parses PRT files. The vulnerability requires user interaction, such as opening a malicious file, and can be triggered by an unauthenticated user.
Business impact
The potential for arbitrary code execution poses a significant threat to business operations, as it could allow an attacker to gain control over affected workstations. Given the CVSS score of 7.8, this vulnerability is considered high risk, as it may lead to total compromise of confidentiality, integrity, and availability within the context of the user process.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.7.0.10 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or unauthorized process execution associated with file parsing activities.
Compensating Controls: Ensure that users are instructed not to open untrusted or unexpected PRT files, and utilize endpoint detection and response tools to monitor for malicious activity initiated by Autodesk applications.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Autodesk software must prioritize updating the affected Shared Components to the latest version. Given the potential for arbitrary code execution, failure to patch these components leaves endpoints vulnerable to exploitation through malicious file delivery.