CVE-2025-9456
7.8Autodesk · Shared Components
A memory corruption vulnerability in Autodesk Shared Components allows arbitrary code execution via a maliciously crafted SLDPRT file.
Executive summary
A memory corruption flaw in Autodesk Shared Components allows an attacker to execute arbitrary code, posing a significant risk to system integrity.
Vulnerability
This is an out-of-bounds write vulnerability (CWE-787) triggered when parsing a malicious SLDPRT file. The vulnerability allows an unauthenticated attacker to execute arbitrary code within the context of the current process, provided they can induce a user to open the crafted file.
Business impact
The potential for arbitrary code execution grants an attacker full control over the affected process, which can lead to data theft, unauthorized system modification, or further lateral movement within the network. With a CVSS score of 7.8, this vulnerability is classified as High severity. The requirement for user interaction via a malicious file does not diminish the risk, as such files are frequently distributed via phishing or compromised collaborative platforms, potentially leading to widespread organizational impact.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official Autodesk security advisory.
Proactive Monitoring: Monitor workstation and server logs for abnormal application crashes or unauthorized process execution associated with Autodesk products.
Compensating Controls: Implement endpoint protection solutions capable of detecting malicious file structures and restrict the execution of untrusted or externally sourced SLDPRT files.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential remote code execution, organizations using Autodesk software must prioritize the deployment of the vendor-provided patch. Administrators should verify the version of Autodesk Shared Components across all endpoints and apply the update immediately to neutralize this threat.