CVE-2025-9457
7.8Autodesk · Shared Components
A heap-based buffer overflow in Autodesk Shared Components allows arbitrary code execution when parsing a maliciously crafted PRT file.
Executive summary
A heap-based memory corruption vulnerability in Autodesk Shared Components could allow an attacker to execute arbitrary code via a malicious PRT file.
Vulnerability
This is a heap-based buffer overflow (CWE-122) triggered when the software parses a malformed PRT file. The vulnerability requires user interaction to open the malicious file, but it does not require authentication to trigger.
Business impact
The ability for an attacker to execute arbitrary code in the context of the current process presents a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, or the deployment of persistent malware within the workstation environment. Given the CVSS score of 7.8, this flaw is categorized as High severity and requires prompt attention to prevent potential lateral movement within the network.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the Autodesk security advisory ADSK-SA-2025-0024.
Proactive Monitoring: Monitor workstation endpoint logs for abnormal application crashes or unexpected processes spawned by Autodesk software.
Compensating Controls: Implement strict email and file transfer filtering to prevent the delivery of untrusted PRT files from unknown or unverified sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Autodesk software should prioritize the identification and patching of the affected Shared Components. Because this vulnerability allows for arbitrary code execution, it poses a significant threat to endpoint integrity. Administrators should ensure that all instances of the affected software are updated to the patched version immediately to eliminate the risk of memory corruption attacks.