CVE-2025-8894
7.8Autodesk · Revit, Revit LT, AutoCAD, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Mechanical
Certain Autodesk products are vulnerable to a heap-based buffer overflow when parsing malformed PDF files, which may lead to arbitrary code execution or system crashes.
Executive summary
A heap-based buffer overflow in multiple Autodesk products allows a local attacker to execute arbitrary code or cause a system crash via a maliciously crafted PDF file.
Vulnerability
This vulnerability is a heap-based buffer overflow (CWE-122) triggered when the application parses a malformed PDF file, requiring user interaction to execute.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high level of severity due to the potential for arbitrary code execution. Successful exploitation could lead to full system compromise, unauthorized data access, or significant operational disruption through application crashes, posing a substantial risk to intellectual property and design workflows.
Remediation
Immediate Action: Update all affected Autodesk software to the patched versions listed in the vendor security advisory (ADSK-SA-2025-0018) immediately.
Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected processes spawned by the Autodesk suite during file parsing operations.
Compensating Controls: Restrict the opening of untrusted PDF files within the Autodesk environment and maintain strict endpoint protection policies to detect malicious code execution patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, organizations utilizing the affected Autodesk software must prioritize the deployment of vendor-provided patches. Administrators should verify that all instances of Revit and AutoCAD are updated to the specified secure versions to eliminate this critical attack vector.