CVE-2025-7675

7.8

Autodesk · AutoCAD and Shared Components

A crafted 3DM file can cause an Out-of-Bounds Write vulnerability in Autodesk products, potentially leading to arbitrary code execution.

Executive summary

A critical Out-of-Bounds Write vulnerability in Autodesk AutoCAD and Shared Components poses a significant risk of arbitrary code execution via maliciously crafted 3DM files.

Vulnerability

This is an Out-of-Bounds Write (CWE-787) vulnerability triggered when the software parses a malformed 3DM file. An unauthenticated attacker can exploit this by enticing a user to open a malicious file, potentially resulting in process crashes, data corruption, or arbitrary code execution.

Business impact

The CVSS score of 7.8 indicates a high severity risk, primarily due to the potential for total loss of confidentiality, integrity, and availability within the context of the user process. Successful exploitation could allow an attacker to gain unauthorized control over the workstation, leading to data exfiltration or the installation of persistent malicious software.

Remediation

Immediate Action: Update all instances of Autodesk AutoCAD and Shared Components to the versions specified in the Autodesk security advisory ADSK-SA-2025-0015 immediately.

Proactive Monitoring: Monitor endpoint security logs for unexpected process crashes or unauthorized file system modifications occurring during the execution of AutoCAD.

Compensating Controls: Implement strict email and file handling policies to prevent users from opening 3DM files from untrusted or unknown sources until patches are applied.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant threat to internal systems. Administrators should prioritize the deployment of the vendor-provided updates to all affected environments to eliminate the risk of exploitation.

More Autodesk CVEs

Sources