CVE-2025-9453

7.8

Autodesk · Shared Components

A crafted PRT file parsed by Autodesk Shared Components can trigger an out-of-bounds read, potentially leading to arbitrary code execution, sensitive data disclosure, or system crashes.

Executive summary

Autodesk Shared Components contains an out-of-bounds read vulnerability that could allow an attacker to execute arbitrary code or access sensitive data through a malicious PRT file.

Vulnerability

The vulnerability is an out-of-bounds read (CWE-125) occurring when the software parses a maliciously crafted PRT file. This flaw requires user interaction to open the malicious file, but it does not require authentication to trigger the underlying memory corruption.

Business impact

The vulnerability is rated as High severity with a CVSS score of 7.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute code in the context of the current user, which could result in unauthorized access to sensitive corporate data, lateral movement within the network, or persistent system instability.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.

Proactive Monitoring: Monitor workstation or server logs for unexpected process crashes or abnormal application behavior associated with file parsing modules.

Compensating Controls: Implement strict file access policies and ensure that users are trained to exercise caution when opening PRT files from untrusted or unknown sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this vulnerability and the potential for code execution, organizations should prioritize the deployment of the vendor-provided updates across all affected systems. Users should avoid opening PRT files from untrusted sources until the patch is verified and applied to all Autodesk installations.

More Autodesk CVEs

Sources