CVE-2025-9452
7.8Autodesk · Shared Components
A memory corruption vulnerability in Autodesk Shared Components allows arbitrary code execution when processing a maliciously crafted SLDPRT file.
Executive summary
A memory corruption vulnerability in Autodesk Shared Components poses a high risk of arbitrary code execution via maliciously crafted SLDPRT files.
Vulnerability
This is an out-of-bounds write vulnerability (CWE-787) triggered when the application parses a malformed SLDPRT file. The vulnerability requires user interaction to open the malicious file, and it executes with the privileges of the current user.
Business impact
The potential for arbitrary code execution allows an attacker to compromise the integrity and confidentiality of the host system. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the significant risk of total system impact if a user is successfully coerced into opening a malicious file.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous process behavior following the opening of CAD files.
Compensating Controls: Restrict the opening of untrusted SLDPRT files from external or unverified sources and ensure users operate with the least privilege necessary to perform their tasks.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be treated with high priority. Organizations using affected Autodesk products must verify their current version of Shared Components and apply the recommended update immediately to prevent unauthorized code execution.