CVE-2025-9455

7.8

Autodesk · Shared Components

A vulnerability in Autodesk Shared Components allows for Out-of-Bounds Read when parsing CATPRODUCT files, potentially leading to information disclosure, process crashes, or arbitrary code execution.

Executive summary

A critical Out-of-Bounds Read vulnerability in Autodesk Shared Components could allow a local attacker to execute arbitrary code or disclose sensitive information via a specially crafted CATPRODUCT file.

Vulnerability

This vulnerability involves an Out-of-Bounds Read (CWE-125) triggered when the software parses a malicious CATPRODUCT file. The attack requires user interaction to open the file, but it does not require prior authentication to exploit the underlying flaw in the parsing logic.

Business impact

Successful exploitation of this vulnerability poses a significant risk to organizational data and system integrity. Because the flaw allows for potential arbitrary code execution in the context of the current process, an attacker could gain control over the affected workstation, leading to unauthorized access to sensitive intellectual property or design data. The CVSS score of 7.8 reflects the high impact on confidentiality, integrity, and availability, necessitating prompt patching to prevent compromise.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.

Proactive Monitoring: Monitor endpoint activity for unusual application crashes or unexpected processes spawning from Autodesk design software.

Compensating Controls: Implement file integrity monitoring and restrict the opening of untrusted or externally sourced CAD files within the environment.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the potential for arbitrary code execution and the severity of the flaw, administrators should prioritize the deployment of the vendor-supplied patch. Organizations should verify their software inventory for the affected versions of Autodesk Shared Components and ensure that all design workstations are updated to the secure version immediately to eliminate this attack vector.

More Autodesk CVEs

Sources