CVE-2025-8354
7.8Autodesk · Revit, Revit LT
Autodesk Revit and Revit LT are vulnerable to a type confusion flaw when parsing crafted RFA files, potentially leading to arbitrary code execution.
Executive summary
A critical type confusion vulnerability in Autodesk Revit and Revit LT allows an attacker to execute arbitrary code or corrupt data through a malicious RFA file.
Vulnerability
This is a Type Confusion vulnerability (CWE-843) triggered when the software parses a malformed RFA file. The vulnerability requires user interaction, such as opening a specially crafted file, and can be triggered by an unauthenticated attacker.
Business impact
The potential for arbitrary code execution in the context of the user process poses a significant risk to organizational data and system integrity. Given the CVSS score of 7.8, this flaw is categorized as High severity, as it could allow an attacker to crash the application, compromise design files, or leverage the user's local system privileges to gain further access to the network.
Remediation
Immediate Action: Update all instances of Autodesk Revit and Revit LT to the patched versions (2026.3, 2025.4.4, or 2024.3.4, respectively) via the Autodesk Access portal.
Proactive Monitoring: Monitor workstation logs for unexpected application crashes or unauthorized file access attempts originating from the Revit process.
Compensating Controls: Implement strict email filtering and endpoint protection policies to prevent users from opening untrusted or unsolicited RFA files from unknown sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should prioritize patching affected Autodesk Revit environments immediately to eliminate the risk of arbitrary code execution. Because this vulnerability relies on the processing of external RFA files, IT teams should also emphasize secure file handling practices to users until all workstations are confirmed to be running the corrected software versions.