CVE-2025-9458

7.8

Autodesk · Shared Components

A memory corruption vulnerability in Autodesk Shared Components allows arbitrary code execution via a maliciously crafted PRT file.

Executive summary

A heap-based buffer overflow in Autodesk Shared Components poses a critical risk of arbitrary code execution to users opening malicious PRT files.

Vulnerability

This is a heap-based buffer overflow (CWE-122) triggered when the software parses a specifically crafted PRT file. The vulnerability allows an unauthenticated attacker to achieve arbitrary code execution within the context of the user process.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high level of risk. Successful exploitation grants an attacker the ability to execute code with the privileges of the victim, which could lead to complete system compromise, the theft of sensitive engineering data, or the installation of persistent malware.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.8.0.7 or later as specified in the official Autodesk security advisory.

Proactive Monitoring: Review endpoint logs for abnormal application crashes or unexpected child processes spawned by Autodesk software while processing PRT files.

Compensating Controls: Ensure that users are instructed to only open PRT files from trusted sources and consider implementing endpoint detection and response solutions to identify suspicious memory operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, organizations utilizing Autodesk products must prioritize the deployment of the vendor-provided security update. Administrators should verify that all instances of Autodesk Shared Components are updated to the patched version to neutralize this high-severity vector.

More Autodesk CVEs

Sources