CVE-2025-9460
7.8Autodesk · Shared Components
A maliciously crafted SLDPRT file parsed by Autodesk Shared Components can trigger an Out-of-Bounds Read, potentially leading to arbitrary code execution.
Executive summary
Autodesk Shared Components contain an Out-of-Bounds Read vulnerability that could allow a remote attacker to execute arbitrary code or access sensitive data through a crafted SLDPRT file.
Vulnerability
This vulnerability is an Out-of-Bounds Read (CWE-125) occurring when the application processes a malformed SLDPRT file. The flaw can be triggered by an unauthenticated user, provided they can induce a victim to open a malicious file within the affected product.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting its potential for total loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, which could result in full system compromise, data exfiltration, or the installation of persistent malicious software.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official vendor advisory (ADSK-SA-2025-0024).
Proactive Monitoring: Monitor system logs for unexpected application crashes or unauthorized process execution originating from file-parsing components.
Compensating Controls: Implement strict email filtering and endpoint protection policies to block or scan suspicious SLDPRT files before they are processed by end-user workstations.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the potential for remote code execution, this vulnerability poses a high risk to organizational security. Administrators must prioritize updating all instances of the affected Autodesk Shared Components to the patched version to prevent potential exploitation. If patching is not immediately feasible, restrict the ability of users to open untrusted SLDPRT files.