CVE-2025-9454
7.8Autodesk · Shared Components
A maliciously crafted PRT file parsed by Autodesk Shared Components can trigger an out-of-bounds read, potentially leading to arbitrary code execution.
Executive summary
Autodesk Shared Components contain an out-of-bounds read vulnerability that may allow a local attacker to crash the system, access sensitive data, or achieve arbitrary code execution.
Vulnerability
This vulnerability is an out-of-bounds read (CWE-125) triggered when the software parses a malformed PRT file. The vulnerability requires user interaction to open the malicious file and can be exploited by an unauthenticated attacker to execute code in the context of the current process.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it allows attackers to bypass standard protections and gain unauthorized control over affected workstations. With a CVSS score of 7.8, this high-severity flaw threatens the confidentiality, integrity, and availability of sensitive design data stored within the Autodesk environment.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Review system and application logs for unusual crashes or unauthorized access patterns specifically associated with the parsing of PRT files.
Compensating Controls: Implement strict file-handling policies that restrict the opening of PRT files from untrusted or external sources until the security update is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for code execution and the high CVSS severity rating, organizations should prioritize patching all systems utilizing the affected Autodesk Shared Components. Administrators must ensure that the update to version 1.9.0.7 is deployed across all production environments immediately to mitigate the risk of exploitation.