CVE-2025-8893

7.8

Autodesk · Revit, Revit LT, AutoCAD, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Mechanical

A maliciously crafted PDF file can trigger an Out-of-Bounds Write vulnerability in various Autodesk products, potentially leading to arbitrary code execution.

Executive summary

A critical Out-of-Bounds Write vulnerability in multiple Autodesk products allows a remote attacker to execute arbitrary code or corrupt data by enticing a user to open a malicious PDF file.

Vulnerability

The software fails to properly validate PDF file inputs, resulting in an Out-of-Bounds Write (CWE-787) when processing malicious files. Exploitation requires user interaction to open the file, but does not require authentication from the attacker.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for total system compromise if successfully exploited. Successful execution could lead to unauthorized data access, system crashes, or the installation of malicious software, posing a significant threat to intellectual property and operational continuity. Given that these products are widely used in engineering and design environments, the risk of targeted attacks via malicious project files is substantial.

Remediation

Immediate Action: Apply the specific security updates provided by Autodesk for each affected product version listed in the vendor security advisory.

Proactive Monitoring: Monitor endpoint execution logs for suspicious processes spawned by Autodesk software and review file access patterns for unexpected PDF imports.

Compensating Controls: Implement file inspection protocols for incoming PDF documents and restrict the execution of software with elevated privileges in environments where untrusted files are handled.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Autodesk customers must prioritize the deployment of the vendor-supplied patches to mitigate this high-severity risk. Given the nature of the vulnerability, organizations should ensure that all design software is updated to the latest secure versions and restrict the opening of PDF files from untrusted sources within the application context. Failure to patch leaves systems vulnerable to code execution attacks that could bypass standard security controls.

More Autodesk CVEs

Sources